vendor:
Java
by:
GuHe
N/A
CVSS
N/A
Heap Buffer Overflow
119
CWE
Product Name: Java
Affected Version From: JRE 7 update 21 and earlier
Affected Version To: JRE 6 update 45 and earlier
Patch Exists: YES
Related CWE: CVE-2013-2470
CPE: a:oracle:java
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2014-0414/, https://www.rapid7.com/db/vulnerabilities/apple-java-cve-2013-2464/, https://www.rapid7.com/db/vulnerabilities/apple-java-cve-2013-2470/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2013-2470/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2013-2464/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-1455/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2013-2470/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2013-2464/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2013-2464/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2013-2470/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2013-2470/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-0957/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-0963/, https://www.rapid7.com/db/vulnerabilities/jre-vuln-cve-2013-2464/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-0958/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-1014/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-1059/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-1060/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-1456/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2013-1081/, https://www.rapid7.com/db/?q=CVE-2013-2470&type=&page=2, https://www.rapid7.com/db/?q=CVE-2013-2470&type=&page=2
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2013
Oracle Java lookupByteBI function heap buffer overflow
The 'Java_sun_awt_image_ImagingLib_lookupByteBI' performs byte lookup operation on two BufferedImage. It tries to map data in src raster to the dst raster. The total bytes written to dst rater buffer is (src->width) * (src->height). However, it does not correctly check the size of the dsata buffer.
Mitigation:
Upgrade to the latest version of Oracle Java.