CVE-2013-1571

Severity

43%

Complexity

86%

Confidentiality

48%

Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html 'Applies to the Javadoc tool and documentation generated by the tool. This vulnerability can be exploited only through Javadoc output hosted on a web server. This addresses CERT/CC VU#225657.'

Unspecified vulnerability in the Javadoc component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier; JavaFX 2.2.21 and earlier; and OpenJDK 7 allows remote attackers to affect integrity via unknown vectors related to Javadoc. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to frame injection in HTML that is generated by Javadoc.

Per: http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html 'Applies to the Javadoc tool and documentation generated by the tool. This vulnerability can be exploited only through Javadoc output hosted on a web server. This addresses CERT/CC VU#225657.'

CVSS 2.0 Base Score 4.3. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).

Overview

First reported 11 years ago

2013-06-18 22:55:00

Last updated 5 years ago

2019-04-15 16:29:00

Affected Software

Oracle JDK 1.6.0 Update 22

1.6.0

Oracle JDK 1.6.0 Update 23

1.6.0

Oracle JDK 1.6.0 Update 24

1.6.0

Oracle JDK 1.6.0 Update 25

1.6.0

Oracle JDK 1.6.0 Update 26

1.6.0

Oracle JDK 1.6.0 Update 27

1.6.0

Oracle JDK 1.6.0 Update 29

1.6.0

Oracle JDK 1.6.0 Update 30

1.6.0

Oracle JDK 1.6.0 Update 31

1.6.0

Oracle JDK 1.6.0 Update 32

1.6.0

Oracle JDK 1.6.0 Update 33

1.6.0

Oracle JDK 1.6.0 Update 34

1.6.0

Oracle JDK 1.6.0 Update 35

1.6.0

Oracle JDK 1.6.0 Update 37

1.6.0

Oracle JDK 1.6.0 Update 38

1.6.0

Oracle JDK 1.6.0 Update 39

1.6.0

Oracle JDK 1.6.0 Update 41

1.6.0

Oracle JDK 1.6.0 Update 43

1.6.0

Sun JDK 1.6.0

1.6.0

Sun JDK 6 Update 1

1.6.0

Sun JDK 1.6.0_01-b06

1.6.0

Sun JDK 6 Update 2

1.6.0

Sun JDK 1.6.0 Update 10

1.6.0

Sun JDK 1.6.0 Update 11

1.6.0

Sun JDK 1.6.0 Update 12

1.6.0

Sun JDK 1.6.0 Update 13

1.6.0

Sun JDK 1.6.0 Update 14

1.6.0

Sun JDK 1.6.0 Update 15

1.6.0

Sun JDK 1.6.0 Update 16

1.6.0

Sun JDK 1.6.0 Update 17

1.6.0

Sun JDK 1.6.0 Update 18

1.6.0

Sun JDK 1.6.0 Update 19

1.6.0

Sun JDK 1.6.0 Update 20

1.6.0

Sun JDK 1.6.0 Update 21

1.6.0

Sun JDK 1.6.0 Update 3

1.6.0

Sun JDK 1.6.0 Update 4

1.6.0

Sun JDK 1.6.0 Update 5

1.6.0

Sun JDK 1.6.0 Update 6

1.6.0

Sun JDK 1.6.0 Update 7

1.6.0

Oracle JDK 1.7.0

1.7.0

Oracle JDK 1.7.0 update1

1.7.0

Oracle JDK 1.7.0 Update 10

1.7.0

Oracle JDK 1.7.0 Update 11

1.7.0

Oracle JDK 1.7.0 Update 13

1.7.0

Oracle JDK 1.7.0 Update 15

1.7.0

Oracle JDK 1.7.0 Update 17

1.7.0

Oracle JDK 1.7.0 update2

1.7.0

Oracle JDK 1.7.0 update3

1.7.0

Oracle JDK 1.7.0 Update 4

1.7.0

Oracle JDK 1.7.0 Update 5

1.7.0

Oracle JDK 1.7.0 Update 6

1.7.0

Oracle JDK 1.7.0 Update 7

1.7.0

Oracle JDK 1.7.0 Update 9

1.7.0

Oracle JDK 1.5.0 Update 36

1.5.0

Oracle JDK 1.5.0 Update 38

1.5.0

Oracle JDK 1.5.0 Update 39

1.5.0

Oracle JDK 1.5.0 Update 40

1.5.0

Oracle JDK 1.5.0 Update 41

1.5.0

Sun JDK 1.5.0

1.5.0

Sun JDK 5.0 Update1

1.5.0

Sun JDK 5.0 Update10

1.5.0

Sun JDK 5.0 Update11

1.5.0

Sun JDK 1.5.0_11 b03

1.5.0

Sun JDK 5.0 Update12

1.5.0

Sun JDK 5.0 Update 13

1.5.0

Sun JDK 5.0 Update 14

1.5.0

Sun JDK 5.0 Update 15

1.5.0

Sun JDK 5.0 Update 16

1.5.0

Sun JDK 5.0 Update 17

1.5.0

Sun JDK 5.0 Update 18

1.5.0

Sun JDK 5.0 Update 19

1.5.0

Sun JDK 5.0 Update2

1.5.0

Sun JDK 5.0 Update 20

1.5.0

Sun JDK 5.0 Update 21

1.5.0

Sun JDK 5.0 Update 22

1.5.0

Sun JDK 5.0 Update 23

1.5.0

Sun JDK 5.0 Update 24

1.5.0

Sun JDK 5.0 Update 25

1.5.0

Sun JDK 5.0 Update 26

1.5.0

Sun JDK 5.0 Update 27

1.5.0

Sun JDK 5.0 Update 28

1.5.0

Sun JDK 5.0 Update 29

1.5.0

Sun JDK 5.0 Update3

1.5.0

Sun JDK 5.0 Update 31

1.5.0

Sun JDK 1.5.0_33 (JDK 5.0 Update 33)

1.5.0

Sun JDK 5.0 Update4

1.5.0

Sun JDK 5.0 Update5

1.5.0

Sun JDK 1.5.0_6

1.5.0

Sun JDK 5.0 Update7

1.5.0

Sun JDK 1.5 _07-b03

1.5.0

Sun JDK 5.0 Update8

1.5.0

Sun JDK 5.0 Update9

1.5.0

Oracle JRE 1.5.0_36 (JRE 5.0 Update 36)

1.5.0

Oracle JRE 1.5.0_38 (Update 38)

1.5.0

Oracle JRE 1.5.0_39 (Update 39)

1.5.0

Oracle JRE 1.5.0_40 (Update 40)

1.5.0

Oracle JRE 1.5.0_41 (Update 41)

1.5.0

Sun JRE 1.5.0

1.5.0

Sun JRE 1.5.0_1 (JRE 5.0 Update 1)

1.5.0

Sun JRE 1.5.0_10 (JRE 5.0 Update 10)

1.5.0

Sun JRE 1.5.0_11 (JRE 5.0 Update 11)

1.5.0

Sun JRE 1.5.0_12 (JRE 5.0 Update 12)

1.5.0

Sun JRE 1.5.0_13 (JRE 5.0 Update 13)

1.5.0

Sun JRE 1.5.0_14 (JRE 5.0 Update 14)

1.5.0

Sun JRE 1.5.0_15 (JRE 5.0 Update 15)

1.5.0

Sun JRE 1.5.0_16 (JRE 5.0 Update 16)

1.5.0

Sun JRE 1.5.0_17 (JRE 5.0 Update 17)

1.5.0

Sun JRE 1.5.0_18 (JRE 5.0 Update 18)

1.5.0

Sun JRE 1.5.0_19 (JRE 5.0 Update 19)

1.5.0

Sun JRE 1.5.0_2 (JRE 5.0 Update 2)

1.5.0

Sun JRE 1.5.0_20 (JRE 5.0 Update 20)

1.5.0

Sun JRE 1.5.0_21 (JRE 5.0 Update 21)

1.5.0

Sun JRE 1.5.0_22 (JRE 5.0 Update 22)

1.5.0

Sun JRE 1.5.0_23 (JRE 5.0 Update 23)

1.5.0

Sun JRE 1.5.0_24 (JRE 5.0 Update 24)

1.5.0

Sun JRE 1.5.0_25 (JRE 5.0 Update 25)

1.5.0

Sun JRE 1.5.0_26 (JRE 5.0 Update 26)

1.5.0

Sun JRE 1.5.0_27 (JRE 5.0 Update 27)

1.5.0

Sun JRE 1.5.0_28 (JRE 5.0 Update 28)

1.5.0

Sun JRE 1.5.0_29 (JRE 5.0 Update 29)

1.5.0

Sun JRE 1.5.0_3 (JRE 5.0 Update 3)

1.5.0

Sun JRE 1.5.0_31 (JRE 5.0 Update 31)

1.5.0

Sun JRE 1.5.0_33 (JRE 5.0 Update 33)

1.5.0

Sun JRE 1.5.0_4 (JRE 5.0 Update 4)

1.5.0

Sun JRE 1.5.0_5 (JRE 5.0 Update 5)

1.5.0

Sun JRE 1.5.0_6 (JRE 5.0 Update 6)

1.5.0

Sun JRE 1.5.0_7 (JRE 5.0 Update 7)

1.5.0

Sun JRE 1.5.0_8 (JRE 5.0 Update 8)

1.5.0

Sun JRE 1.5.0_9 (JRE 5.0 Update 9)

1.5.0

Oracle JRE 1.7.0

1.7.0

Oracle JRE 1.7.0 update1

1.7.0

Oracle JRE 1.7.0 Update 10

1.7.0

Oracle JRE 1.7.0 Update 11

1.7.0

Oracle JRE 1.7.0 Update 13

1.7.0

Oracle JRE 1.7.0 Update 15

1.7.0

Oracle JRE 1.7.0 Update 17

1.7.0

Oracle JRE 1.7.0 update2

1.7.0

Oracle JRE 1.7.0 update3

1.7.0

Oracle JRE 1.7.0 Update 4

1.7.0

Oracle JRE 1.7.0 Update 5

1.7.0

Oracle JRE 1.7.0 Update 6

1.7.0

Oracle JRE 1.7.0 Update 7

1.7.0

Oracle JRE 1.7.0 Update 9

1.7.0

Oracle JRE 1.6.0 Update 22

1.6.0

Oracle JRE 1.6.0 Update 23

1.6.0

Oracle JRE 1.6.0 Update 24

1.6.0

Oracle JRE 1.6.0 Update 25

1.6.0

Oracle JRE 1.6.0 Update 26

1.6.0

Oracle JRE 1.6.0 Update 27

1.6.0

Oracle JRE 1.6.0 Update 29

1.6.0

Oracle JRE 1.6.0 Update 30

1.6.0

Oracle JRE 1.6.0 Update 31

1.6.0

Oracle JRE 1.6.0 Update 32

1.6.0

Oracle JRE 1.6.0 Update 33

1.6.0

Oracle JRE 1.6.0 Update 34

1.6.0

Oracle JRE 1.6.0 Update 35

1.6.0

Oracle JRE 1.6.0 Update 37

1.6.0

Oracle JRE 1.6.0 Update 38

1.6.0

Oracle JRE 1.6.0 Update 39

1.6.0

Oracle JRE 1.6.0 Update 41

1.6.0

Oracle JRE 1.6.0 Update 43

1.6.0

Sun JRE 1.6.0

1.6.0

Sun JRE 1.6.0 Update 1

1.6.0

Sun JRE 1.6.0 Update 10

1.6.0

Sun JRE 1.6.0 Update 11

1.6.0

Sun JRE 1.6.0 Update 12

1.6.0

Sun JRE 1.6.0 Update 13

1.6.0

Sun JRE 1.6.0 Update 14

1.6.0

Sun JRE 1.6.0 Update 15

1.6.0

Sun JRE 1.6.0 Update 16

1.6.0

Sun JRE 1.6.0 Update 17

1.6.0

Sun JRE 1.6.0 Update 18

1.6.0

Sun JRE 1.6.0 Update 19

1.6.0

Sun JRE 1.6.0 Update 2

1.6.0

Sun JRE 1.6.0 Update 20

1.6.0

Sun JRE 1.6.0 Update 21

1.6.0

Sun JRE 1.6.0 Update 3

1.6.0

Sun JRE 1.6.0 Update 4

1.6.0

Sun JRE 1.6.0 Update 5

1.6.0

Sun JRE 1.6.0 Update 6

1.6.0

Sun JRE 1.6.0 Update 7

1.6.0

Sun JRE 1.6.0 Update 9

1.6.0

Oracle JavaFX 2.0

2.0

Oracle JavaFX 2.0.2

2.0.2

Oracle JavaFX 2.0.3

2.0.3

Oracle JavaFX 2.1

2.1

Oracle JavaFX 2.2

2.2

Oracle JavaFX 2.2.3

2.2.3

Oracle JavaFX 2.2.4

2.2.4

Oracle JavaFX 2.2.5

2.2.5

Oracle JavaFX 2.2.7

2.2.7

References

http://advisories.mageia.org/MGASA-2013-0185.html

SSRT101305

http://hg.openjdk.java.net/jdk7u/jdk7u-dev/langtools/rev/17ee569d0c01

Exploit, Patch

SUSE-SU-2013:1255

SUSE-SU-2013:1257

SUSE-SU-2013:1263

SUSE-SU-2013:1293

SUSE-SU-2013:1305

HPSBUX02907

HPSBUX02908

RHSA-2013:0963

RHSA-2013:1059

RHSA-2013:1060

RHSA-2013:1081

RHSA-2013:1455

RHSA-2013:1456

54154

Vendor Advisory

GLSA-201406-32

VU#225657

US Government Resource

MDVSA-2013:183

http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html

Vendor Advisory

60634

TA13-169A

US Government Resource

http://www-01.ibm.com/support/docview.wss?uid=swg21642336

http://www-01.ibm.com/support/docview.wss?uid=swg21644197

RHSA-2014:0414

https://bugzilla.redhat.com/show_bug.cgi?id=973474

Patch

[tomcat-dev] 20190413 svn commit: r1857494 [15/20] - in /tomcat/site/trunk: ./ docs/ xdocs/

[tomcat-dev] 20190325 svn commit: r1856174 [21/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/

[tomcat-dev] 20190415 svn commit: r1857582 [16/22] - in /tomcat/site/trunk: docs/ xdocs/stylesheets/

[tomcat-dev] 20190319 svn commit: r1855831 [23/30] - in /tomcat/site/trunk: ./ docs/ xdocs/

[tomcat-dev] 20200203 svn commit: r1873527 [23/30] - /tomcat/site/trunk/docs/

[tomcat-dev] 20200213 svn commit: r1873980 [26/34] - /tomcat/site/trunk/docs/

[openoffice-commits] 20200305 svn commit: r1874832 - in /openoffice/ooo-site/trunk/content: download/checksums.html download/globalvars.js download/test/globalvars.js security/cves/CVE-2012-0037.html security/cves/CVE-2013-1571.html

oval:org.mitre.oval:def:17215

oval:org.mitre.oval:def:19518

oval:org.mitre.oval:def:19667

oval:org.mitre.oval:def:19718

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.