CVE-2013-2419
Summary
| CVE | CVE-2013-2419 |
|---|---|
| State | PUBLISHED |
| Assigner | oracle |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-04-17 18:55:06 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect availability via unknown vectors related to 2D. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "font processing errors" in the International Components for Unicode (ICU) Layout Engine before 51.2. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:P
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Jdk | 1.5.0 | update36 | All | All |
| Application | Oracle | Jdk | 1.5.0 | update38 | All | All |
| Application | Oracle | Jdk | 1.5.0 | update40 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update22 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update23 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update24 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update25 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update26 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update27 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update29 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update30 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update31 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update32 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update33 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update34 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update35 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update37 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update38 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update39 | All | All |
| Application | Oracle | Jdk | 1.6.0 | update41 | All | All |
| Application | Oracle | Jdk | 1.7.0 | All | All | All |
| Application | Oracle | Jdk | 1.7.0 | update1 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update10 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update11 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update13 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update15 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update2 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update3 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update4 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update5 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update6 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update7 | All | All |
| Application | Oracle | Jdk | 1.7.0 | update9 | All | All |
| Application | Oracle | Jdk | All | update41 | All | All |
| Application | Oracle | Jdk | All | update43 | All | All |
| Application | Oracle | Jdk | All | update17 | All | All |
| Application | Oracle | Jre | 1.5.0 | update36 | All | All |
| Application | Oracle | Jre | 1.5.0 | update38 | All | All |
| Application | Oracle | Jre | 1.5.0 | update40 | All | All |
| Application | Oracle | Jre | 1.6.0 | update22 | All | All |
| Application | Oracle | Jre | 1.6.0 | update23 | All | All |
| Application | Oracle | Jre | 1.6.0 | update24 | All | All |
| Application | Oracle | Jre | 1.6.0 | update25 | All | All |
| Application | Oracle | Jre | 1.6.0 | update26 | All | All |
| Application | Oracle | Jre | 1.6.0 | update27 | All | All |
| Application | Oracle | Jre | 1.6.0 | update29 | All | All |
| Application | Oracle | Jre | 1.6.0 | update30 | All | All |
| Application | Oracle | Jre | 1.6.0 | update31 | All | All |
| Application | Oracle | Jre | 1.6.0 | update32 | All | All |
| Application | Oracle | Jre | 1.6.0 | update33 | All | All |
| Application | Oracle | Jre | 1.6.0 | update34 | All | All |
| Application | Oracle | Jre | 1.6.0 | update35 | All | All |
| Application | Oracle | Jre | 1.6.0 | update37 | All | All |
| Application | Oracle | Jre | 1.6.0 | update38 | All | All |
| Application | Oracle | Jre | 1.6.0 | update39 | All | All |
| Application | Oracle | Jre | 1.6.0 | update41 | All | All |
| Application | Oracle | Jre | 1.7.0 | All | All | All |
| Application | Oracle | Jre | 1.7.0 | update1 | All | All |
| Application | Oracle | Jre | 1.7.0 | update10 | All | All |
| Application | Oracle | Jre | 1.7.0 | update11 | All | All |
| Application | Oracle | Jre | 1.7.0 | update13 | All | All |
| Application | Oracle | Jre | 1.7.0 | update15 | All | All |
| Application | Oracle | Jre | 1.7.0 | update2 | All | All |
| Application | Oracle | Jre | 1.7.0 | update3 | All | All |
| Application | Oracle | Jre | 1.7.0 | update4 | All | All |
| Application | Oracle | Jre | 1.7.0 | update5 | All | All |
| Application | Oracle | Jre | 1.7.0 | update6 | All | All |
| Application | Oracle | Jre | 1.7.0 | update7 | All | All |
| Application | Oracle | Jre | 1.7.0 | update9 | All | All |
| Application | Oracle | Jre | All | update41 | All | All |
| Application | Oracle | Jre | All | update43 | All | All |
| Application | Oracle | Jre | All | update17 | All | All |
| Application | Sun | Jdk | 1.5.0 | All | All | All |
| Application | Sun | Jdk | 1.5.0 | update1 | All | All |
| Application | Sun | Jdk | 1.5.0 | update10 | All | All |
| Application | Sun | Jdk | 1.5.0 | update11 | All | All |
| Application | Sun | Jdk | 1.5.0 | update11_b03 | All | All |
| Application | Sun | Jdk | 1.5.0 | update12 | All | All |
| Application | Sun | Jdk | 1.5.0 | update13 | All | All |
| Application | Sun | Jdk | 1.5.0 | update14 | All | All |
| Application | Sun | Jdk | 1.5.0 | update15 | All | All |
| Application | Sun | Jdk | 1.5.0 | update16 | All | All |
| Application | Sun | Jdk | 1.5.0 | update17 | All | All |
| Application | Sun | Jdk | 1.5.0 | update18 | All | All |
| Application | Sun | Jdk | 1.5.0 | update19 | All | All |
| Application | Sun | Jdk | 1.5.0 | update2 | All | All |
| Application | Sun | Jdk | 1.5.0 | update20 | All | All |
| Application | Sun | Jdk | 1.5.0 | update21 | All | All |
| Application | Sun | Jdk | 1.5.0 | update22 | All | All |
| Application | Sun | Jdk | 1.5.0 | update23 | All | All |
| Application | Sun | Jdk | 1.5.0 | update24 | All | All |
| Application | Sun | Jdk | 1.5.0 | update25 | All | All |
| Application | Sun | Jdk | 1.5.0 | update26 | All | All |
| Application | Sun | Jdk | 1.5.0 | update27 | All | All |
| Application | Sun | Jdk | 1.5.0 | update28 | All | All |
| Application | Sun | Jdk | 1.5.0 | update29 | All | All |
| Application | Sun | Jdk | 1.5.0 | update3 | All | All |
| Application | Sun | Jdk | 1.5.0 | update31 | All | All |
| Application | Sun | Jdk | 1.5.0 | update33 | All | All |
| Application | Sun | Jdk | 1.5.0 | update4 | All | All |
| Application | Sun | Jdk | 1.5.0 | update5 | All | All |
| Application | Sun | Jdk | 1.5.0 | update6 | All | All |
| Application | Sun | Jdk | 1.5.0 | update7 | All | All |
| Application | Sun | Jdk | 1.5.0 | update7_b03 | All | All |
| Application | Sun | Jdk | 1.5.0 | update8 | All | All |
| Application | Sun | Jdk | 1.5.0 | update9 | All | All |
| Application | Sun | Jdk | 1.6.0 | All | All | All |
| Application | Sun | Jdk | 1.6.0 | update1 | All | All |
| Application | Sun | Jdk | 1.6.0 | update1_b06 | All | All |
| Application | Sun | Jdk | 1.6.0 | update2 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_10 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_11 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_12 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_13 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_14 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_15 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_16 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_17 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_18 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_19 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_20 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_21 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_3 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_4 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_5 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_6 | All | All |
| Application | Sun | Jdk | 1.6.0 | update_7 | All | All |
| Application | Sun | Jre | 1.5.0 | All | All | All |
| Application | Sun | Jre | 1.5.0 | update1 | All | All |
| Application | Sun | Jre | 1.5.0 | update10 | All | All |
| Application | Sun | Jre | 1.5.0 | update11 | All | All |
| Application | Sun | Jre | 1.5.0 | update12 | All | All |
| Application | Sun | Jre | 1.5.0 | update13 | All | All |
| Application | Sun | Jre | 1.5.0 | update14 | All | All |
| Application | Sun | Jre | 1.5.0 | update15 | All | All |
| Application | Sun | Jre | 1.5.0 | update16 | All | All |
| Application | Sun | Jre | 1.5.0 | update17 | All | All |
| Application | Sun | Jre | 1.5.0 | update18 | All | All |
| Application | Sun | Jre | 1.5.0 | update19 | All | All |
| Application | Sun | Jre | 1.5.0 | update2 | All | All |
| Application | Sun | Jre | 1.5.0 | update20 | All | All |
| Application | Sun | Jre | 1.5.0 | update21 | All | All |
| Application | Sun | Jre | 1.5.0 | update22 | All | All |
| Application | Sun | Jre | 1.5.0 | update23 | All | All |
| Application | Sun | Jre | 1.5.0 | update24 | All | All |
| Application | Sun | Jre | 1.5.0 | update25 | All | All |
| Application | Sun | Jre | 1.5.0 | update26 | All | All |
| Application | Sun | Jre | 1.5.0 | update27 | All | All |
| Application | Sun | Jre | 1.5.0 | update28 | All | All |
| Application | Sun | Jre | 1.5.0 | update29 | All | All |
| Application | Sun | Jre | 1.5.0 | update3 | All | All |
| Application | Sun | Jre | 1.5.0 | update31 | All | All |
| Application | Sun | Jre | 1.5.0 | update33 | All | All |
| Application | Sun | Jre | 1.5.0 | update4 | All | All |
| Application | Sun | Jre | 1.5.0 | update5 | All | All |
| Application | Sun | Jre | 1.5.0 | update6 | All | All |
| Application | Sun | Jre | 1.5.0 | update7 | All | All |
| Application | Sun | Jre | 1.5.0 | update8 | All | All |
| Application | Sun | Jre | 1.5.0 | update9 | All | All |
| Application | Sun | Jre | 1.6.0 | All | All | All |
| Application | Sun | Jre | 1.6.0 | update_1 | All | All |
| Application | Sun | Jre | 1.6.0 | update_10 | All | All |
| Application | Sun | Jre | 1.6.0 | update_11 | All | All |
| Application | Sun | Jre | 1.6.0 | update_12 | All | All |
| Application | Sun | Jre | 1.6.0 | update_13 | All | All |
| Application | Sun | Jre | 1.6.0 | update_14 | All | All |
| Application | Sun | Jre | 1.6.0 | update_15 | All | All |
| Application | Sun | Jre | 1.6.0 | update_16 | All | All |
| Application | Sun | Jre | 1.6.0 | update_17 | All | All |
| Application | Sun | Jre | 1.6.0 | update_18 | All | All |
| Application | Sun | Jre | 1.6.0 | update_19 | All | All |
| Application | Sun | Jre | 1.6.0 | update_2 | All | All |
| Application | Sun | Jre | 1.6.0 | update_20 | All | All |
| Application | Sun | Jre | 1.6.0 | update_21 | All | All |
| Application | Sun | Jre | 1.6.0 | update_3 | All | All |
| Application | Sun | Jre | 1.6.0 | update_4 | All | All |
| Application | Sun | Jre | 1.6.0 | update_5 | All | All |
| Application | Sun | Jre | 1.6.0 | update_6 | All | All |
| Application | Sun | Jre | 1.6.0 | update_7 | All | All |
| Application | Sun | Jre | 1.6.0 | update_9 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Download ICU 51 - ICU - International Components for Unicode | af854a3a-2127-422b-91ae-364da2661108 | site.icu-project.org | |
| #10107 (Multiple security vulnerabilities in the ICU Layout Engine, all prior versions) – ICU trac | af854a3a-2127-422b-91ae-364da2661108 | bugs.icu-project.org | |
| GNU/Andrew’s Blog » [SECURITY] IcedTea 2.3.9 for OpenJDK 7 Released! | af854a3a-2127-422b-91ae-364da2661108 | blog.fuseyism.com | |
| h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | |
| [security-announce] SUSE-SU-2013:0814-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Oracle Solaris Third Party Bulletin - April 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Bug 952656 – CVE-2013-2419 ICU: Layout Engine font processing errors (JDK 2D, 8001031) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| openSUSE-SU-2013:0777-1: moderate: java-1_6_0-openjdk to Icedtea6-1.12.5 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Support/Advisories/MGASA-2013-0130 - Mageia wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.mageia.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Support / Security / Advisories / / MDVSA-2013:161 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| GNU/Andrew’s Blog » [SECURITY] IcedTea 1.11.11 & 1.12.5 for OpenJDK 6 Released! | af854a3a-2127-422b-91ae-364da2661108 | blog.fuseyism.com | |
| Oracle Java SE CVE-2013-2419 Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Oracle Java SE Critical Patch Update - April 2013 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | Vendor Advisory |
| [SECURITY] IcedTea 1.11.10 for OpenJDK 6 Released! | af854a3a-2127-422b-91ae-364da2661108 | mail.openjdk.java.net | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Oracle Solaris Third Party Bulletin - October 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| [security-announce] SUSE-SU-2013:0835-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Oracle Has Released Multiple Updates for Java SE | US-CERT | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| Gentoo Linux Documentation -- IcedTea JDK: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| '[security bulletin] HPSBUX02889 SSRT101252 rev.1 - HP-UX Running Java, Remote Unauthorized Access, D' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| USN-1806-1: OpenJDK 7 vulnerabilities | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| [security-announce] SUSE-SU-2013:0871-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Support / Security / Advisories / / MDVSA-2013:145 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| APPLE-SA-2013-04-16-2 Java for OS X 2013-003 and Mac OS X v10.6 Update 15 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Support/Advisories/MGASA-2013-0124 - Mageia wiki | af854a3a-2127-422b-91ae-364da2661108 | wiki.mageia.org | |
| [security-announce] SUSE-SU-2013:0934-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| openSUSE-SU-2013:0964-1: moderate: update for java-1_7_0-openjdk | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.