CVE-2012-4305 Information

Description

Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality integrity and availability via unknown vectors a different vulnerability than other CVEs listed in the February 2013 CPU. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from a third party that the issue allows remote attackers to execute arbitrary code via vectors related to an \invalid type cast\ and exposed native methods in the T2KGlyph class.

Reference

http://marc.info/?l=bugtraq&m=136733161405818&w=2 http://www.kb.cert.org/vuls/id/858729 http://www.oracle.com/technetwork/topics/security/javacpufeb2013-1841061.html http://www.us-cert.gov/cas/techalerts/TA13-032A.html http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=1030 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A16392

Share on: