vendor:
Java
by:
Name Withheld
7.5
CVSS
HIGH
Memory Corruption
Unknown
CWE
Product Name: Java
Affected Version From: Prior to 7u25
Affected Version To:
Patch Exists: YES
Related CWE: Unknown
CPE: cpe:2.3:a:oracle:java:*:*:*:*:*:*:*:*
Platforms Tested: Windows, Linux, Mac
2013
Oracle Java ByteComponentRaster.verify() Memory Corruption
The ByteComponentRaster.verify() method in Oracle Java versions prior to 7u25 is vulnerable to a memory corruption vulnerability that allows bypassing of "dataOffsets[]" boundary checks. This vulnerability allows for remote code execution. User interaction is required for this exploit in that the target must visit a malicious page or open a malicious file.
Mitigation:
Update Oracle Java to version 7u25 or later.