User: Password:
|
|
Subscribe / Log in / New account

Scientific Linux alert SL-iced-20130417 (icedtea-web)

From:  Pat Riehecky <riehecky@fnal.gov>
To:  <scientific-linux-errata@listserv.fnal.gov>
Subject:  Security ERRATA Moderate: icedtea-web on SL6.x i386/x86_64
Date:  Wed, 17 Apr 2013 20:52:09 +0000
Message-ID:  <20130417205209.8629.8630@slpackages.fnal.gov>
Archive-link:  Article, Thread

Synopsis: Moderate: icedtea-web security update Advisory ID: SLSA-2013:0753-1 Issue Date: 2013-04-17 CVE Numbers: CVE-2013-1927 CVE-2013-1926 -- It was discovered that the IcedTea-Web plug-in incorrectly used the same class loader instance for applets with the same value of the codebase attribute, even when they originated from different domains. A malicious applet could use this flaw to gain information about and possibly manipulate applets from different domains currently running in the browser. (CVE-2013-1926) The IcedTea-Web plug-in did not properly check the format of the downloaded Java Archive (JAR) files. This could cause the plug-in to execute code hidden in a file in a different format, possibly allowing attackers to execute code in the context of web sites that allow uploads of specific file types, known as a GIFAR attack. (CVE-2013-1927) This erratum also upgrades IcedTea-Web to version 1.2.3. Web browsers using the IcedTea-Web browser plug-in must be restarted for this update to take effect. -- SL6 x86_64 icedtea-web-1.2.3-2.el6_4.x86_64.rpm icedtea-web-debuginfo-1.2.3-2.el6_4.x86_64.rpm icedtea-web-javadoc-1.2.3-2.el6_4.x86_64.rpm i386 icedtea-web-1.2.3-2.el6_4.i686.rpm icedtea-web-debuginfo-1.2.3-2.el6_4.i686.rpm icedtea-web-javadoc-1.2.3-2.el6_4.i686.rpm - Scientific Linux Development Team


(Log in to post comments)


Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds