CVE-2013-5842

Oracle JDK 7u40/6u60/5.0u51 & Java SE Embedded 7u40 - Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-5842. PoCs published by guhe120.

AI-analyzed exploit summary This PoC exploits CVE-2013-5842, a Java deserialization vulnerability, by manipulating object serialization to achieve arbitrary code execution. It uses a multi-threaded approach to leak memory addresses and construct a fake object to bypass security checks.

Description

Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-5850.

Exploits (1)

nomisec WORKING POC 2 stars
by guhe120 · poc
https://github.com/guhe120/CVE-2013-5842

This PoC exploits CVE-2013-5842, a Java deserialization vulnerability, by manipulating object serialization to achieve arbitrary code execution. It uses a multi-threaded approach to leak memory addresses and construct a fake object to bypass security checks.

Classification
Working Poc 95%
Attack Type
Deserialization
Complexity
Complex
Reliability
Racy
Target: Java Runtime Environment (JRE) versions affected by CVE-2013-5842
No auth needed
Prerequisites: Java application that deserializes untrusted data
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (28)

Core 28
Core References
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2014:0414
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201406-32.xml
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1447.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1440.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2033-1
Third Party Advisory, VDB Entry x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-13-246/
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2089-1
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1508.html
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1019123
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=138674073720143&w=2
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1505.html
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21655201
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=138674031212883&w=2
Broken Link vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-11/msg00023.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1793.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1509.html
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2013/Oct/msg00001.html
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1507.html
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT5982
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/63150
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56338
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-1451.html
Broken Link vdb-entry x_refsource_osvdb
http://osvdb.org/98532

Scores

EPSS 0.1761
EPSS Percentile 96.8%

Details

Status published
Products (7)
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 12.10
canonical/ubuntu_linux 13.04
canonical/ubuntu_linux 13.10
oracle/jdk 1.5.0 (43 CPE variants)
oracle/jdk 1.6.0 (2 CPE variants)
Published Oct 16, 2013
Tracked Since Feb 18, 2026