Home
Reading
Searching
Subscribe
Sponsors
Statistics
Posting
Contact
Spam
Lists
Links
About
Hosting
Filtering
Features Download
Marketing
Archives
FAQ
Blog
 
Gmane
From: Pat Riehecky <riehecky-13hema8v3vg <at> public.gmane.org>
Subject: Security ERRATA Moderate: icedtea-web on SL6.x i386/x86_64
Newsgroups: gmane.linux.scientific.errata
Date: Wednesday 17th April 2013 20:52:09 UTC (over 3 years ago)
Synopsis:          Moderate: icedtea-web security update
Advisory ID:       SLSA-2013:0753-1
Issue Date:        2013-04-17
CVE Numbers:       CVE-2013-1927
                   CVE-2013-1926
--

It was discovered that the IcedTea-Web plug-in incorrectly used the same
class loader instance for applets with the same value of the codebase
attribute, even when they originated from different domains. A malicious
applet could use this flaw to gain information about and possibly
manipulate applets from different domains currently running in the
browser. (CVE-2013-1926)

The IcedTea-Web plug-in did not properly check the format of the
downloaded Java Archive (JAR) files. This could cause the plug-in to
execute code hidden in a file in a different format, possibly allowing
attackers to execute code in the context of web sites that allow uploads
of specific file types, known as a GIFAR attack. (CVE-2013-1927)

This erratum also upgrades IcedTea-Web to version 1.2.3.

Web browsers using the IcedTea-Web browser plug-in must be restarted for
this update to take effect.
--

SL6
  x86_64
    icedtea-web-1.2.3-2.el6_4.x86_64.rpm
    icedtea-web-debuginfo-1.2.3-2.el6_4.x86_64.rpm
    icedtea-web-javadoc-1.2.3-2.el6_4.x86_64.rpm
  i386
    icedtea-web-1.2.3-2.el6_4.i686.rpm
    icedtea-web-debuginfo-1.2.3-2.el6_4.i686.rpm
    icedtea-web-javadoc-1.2.3-2.el6_4.i686.rpm

- Scientific Linux Development Team
 
CD: 3ms