vendor:
Java
by:
Name Withheld
7.5
CVSS
HIGH
Integer Overflow
190
CWE
Product Name: Java
Affected Version From: Prior to 7u25
Affected Version To: 7u25
Patch Exists: YES
Related CWE:
CPE: a:oracle:java
Platforms Tested: Windows, Linux, Mac
2013
Oracle Java IntegerInterleavedRaster.verify() Signed Integer Overflow
The IntegerInterleavedRaster.verify() method in Oracle Java versions prior to 7u25 is vulnerable to a signed integer overflow that allows bypassing of 'dataOffsets[0]' boundary checks. This vulnerability allows for remote code execution.
Mitigation:
Upgrade to Oracle Java version 7u25 or later.