LWN.net Logo

icedtea-web: sandboxing failure

Package(s):icedtea-web CVE #(s):CVE-2011-3377
Created:November 9, 2011 Updated:March 14, 2012
Description: A flaw in the same-origin policy implementation in the icedtea-web browser plugin can enable malicious JavaScript code to connect to sites other than the originating host.
Alerts:
Ubuntu USN-1263-1 2011-11-16
Fedora FEDORA-2011-15691 2011-11-10
Red Hat RHSA-2011:1441-01 2011-11-08
openSUSE openSUSE-SU-2011:1251-1 2011-11-16
Mandriva MDVSA-2011:170 2011-11-11
Oracle ELSA-2011-1441 2011-11-09
Fedora FEDORA-2011-15673 2011-11-10
Scientific Linux SL-iced-20111108 2011-11-08
Debian DSA-2420-1 2012-02-28
openSUSE openSUSE-SU-2012:0371-1 2012-03-14

(Log in to post comments)

icedtea-web: sandboxing failure

Posted Nov 12, 2011 7:26 UTC (Sat) by geuder (subscriber, #62854) [Link]

icedtea is about Java, not JavaScript! Netscape's most successful marketing trick, still works 15 years later, although they have long stopped benefitting from it...

icedtea-web: sandboxing failure

Posted Nov 12, 2011 20:48 UTC (Sat) by Tobu (subscriber, #24111) [Link]

I thought it made sense, but I was thinking of IceweaselÂ…

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds