Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" that can trigger an integer overflow and memory corruption.
References
Link Providers
http://icedtea.classpath.org/hg/release/icedtea6-1.11/file/icedtea6-1.11.6/NEWS cve-icon cve-icon
http://icedtea.classpath.org/hg/release/icedtea7-forest-2.3/jdk/rev/d89bd26ac435 cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00001.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00034.html cve-icon cve-icon
http://marc.info/?l=bugtraq&m=136439120408139&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=136570436423916&w=2 cve-icon cve-icon
http://marc.info/?l=bugtraq&m=136733161405818&w=2 cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0236.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0237.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0245.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0246.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-0247.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-1455.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2013-1456.html cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-201406-32.xml cve-icon cve-icon
http://www-01.ibm.com/support/docview.wss?uid=swg21645566 cve-icon cve-icon
http://www.kb.cert.org/vuls/id/858729 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2013:095 cve-icon cve-icon
http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html cve-icon cve-icon cve-icon
http://www.securityfocus.com/bid/57686 cve-icon cve-icon
http://www.us-cert.gov/cas/techalerts/TA13-032A.html cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=906894 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2013-1478 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15733 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19429 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19454 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19529 cve-icon cve-icon
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0056 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2013-1478 cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published: 2013-02-02T00:00:00

Updated: 2024-08-06T15:04:48.678Z

Reserved: 2013-01-30T00:00:00

Link: CVE-2013-1478

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2013-02-02T00:55:02.850

Modified: 2022-05-13T14:52:58.480

Link: CVE-2013-1478

cve-icon Redhat

Severity : Critical

Publid Date: 2013-02-01T00:00:00Z

Links: CVE-2013-1478 - Bugzilla