You are here

CVE-2013-5907

Vincent (CVE) Danen's picture
Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; JRockit R27.7.7 and R28.2.9; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is due to incorrect input validation in LookupProcessor.cpp in the ICU Layout Engine, which allows attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted font file.

Details Source

Mitre

Public Date

2014-01-14 00:00:00

Impact

Critical

Bugzilla

CVE-2013-5907 ICU: Layout Engine LookupProcessor insufficient input checks (JDK 2D, 8025034)

Bugzilla ID

1 052 915

CVSS Status

verified

Base Score

6.80

Base Metrics

AV:N/AC:M/Au:N/C:P/I:P/A:P

External References

http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html

Red Hat Security Errata

Platform Errata Release Date
Red Hat Enterprise Linux Supplementary 5 (java-1.7.0-oracle) RHSA-2014:0030 2014-01-15
Red Hat Enterprise Linux 5 (java-1.6.0-openjdk) RHSA-2014:0097 2014-01-27
Red Hat Enterprise Linux 5 (java-1.7.0-openjdk) RHSA-2014:0027 2014-01-15
Red Hat Satellite 5.6 (RHEL v.5) (java-1.6.0-ibm) RHSA-2014:0982 2014-07-29
Red Hat Enterprise Linux Supplementary 5 (java-1.6.0-ibm) RHSA-2014:0135 2014-02-04
Red Hat Satellite 5.6 (RHEL v.6) (java-1.6.0-ibm) RHSA-2014:0982 2014-07-29
Red Hat Satellite 5.5 (RHEL v.5) (java-1.6.0-ibm) RHSA-2014:0982 2014-07-29
Red Hat Satellite 5.5 (RHEL v.6) (java-1.6.0-ibm) RHSA-2014:0982 2014-07-29
Oracle Java for Red Hat Enterprise Linux 6 (java-1.6.0-sun) RHSA-2014:0414 2014-04-17
Red Hat Enterprise Linux Supplementary (v. 6) (java-1.5.0-ibm) RHSA-2014:0136 2014-02-04
Red Hat Enterprise Linux Supplementary (v. 6) (java-1.6.0-ibm) RHSA-2014:0135 2014-02-04
Red Hat Enterprise Linux Supplementary (v. 6) (java-1.7.0-ibm) RHSA-2014:0134 2014-02-04
Red Hat Enterprise Linux Supplementary 5 (java-1.5.0-ibm) RHSA-2014:0136 2014-02-04
Red Hat Enterprise Linux Supplementary (v. 7) (java-1.7.1-ibm) RHSA-2014:0705 2014-06-10
Red Hat Enterprise Linux Supplementary 5 (java-1.7.0-ibm) RHSA-2014:0134 2014-02-04
Red Hat Enterprise Linux 6 (java-1.7.0-openjdk) RHSA-2014:0026 2014-01-15
Red Hat Enterprise Linux 6 (java-1.6.0-openjdk) RHSA-2014:0097 2014-01-27
Red Hat Satellite 5.4 (RHEL v.6) (java-1.6.0-ibm) RHSA-2014:0982 2014-07-29
Red Hat Satellite 5.4 (RHEL v.5) (java-1.6.0-ibm) RHSA-2014:0982 2014-07-29
Oracle Java for Red Hat Enterprise Linux 5 (java-1.6.0-sun) RHSA-2014:0414 2014-04-17
Red Hat Enterprise Linux Supplementary (v. 6) (java-1.7.0-oracle) RHSA-2014:0030 2014-01-15

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 7 icu Not affected
Red Hat Enterprise Linux 7 java-1.6.0-openjdk Affected
Red Hat Enterprise Linux 7 java-1.7.0-oracle Affected
Red Hat Enterprise Linux 7 java-1.7.0-ibm Affected
Red Hat Enterprise Linux 7 java-1.7.0-openjdk Affected
Red Hat Enterprise Linux 7 java-1.6.0-ibm Affected
Red Hat Enterprise Linux 6 icu Will not fix
Red Hat Enterprise Linux 5 icu Will not fix