First published: Thu Feb 28 2013(Updated: )
It was discovered that IcedTea-Web browser plugin incorrectly used the same class loader for applets with the same codebase paths. The default and commonly used codebase value is ".". A malicious applet could use this flaw to gain information about or possibly manipulate other applets currently running in the browser. This could possibly lead to malicious applet's code being executed as part of the other applet.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/icedtea-web | <1.2.3 | 1.2.3 |
redhat/icedtea-web | <1.3.2 | 1.3.2 |
Redhat Icedtea-web | <=1.2.2 | |
Redhat Icedtea-web | =1.0 | |
Redhat Icedtea-web | =1.0.1 | |
Redhat Icedtea-web | =1.0.2 | |
Redhat Icedtea-web | =1.0.3 | |
Redhat Icedtea-web | =1.0.4 | |
Redhat Icedtea-web | =1.0.5 | |
Redhat Icedtea-web | =1.0.6 | |
Redhat Icedtea-web | =1.1 | |
Redhat Icedtea-web | =1.1.1 | |
Redhat Icedtea-web | =1.1.2 | |
Redhat Icedtea-web | =1.1.3 | |
Redhat Icedtea-web | =1.1.4 | |
Redhat Icedtea-web | =1.1.5 | |
Redhat Icedtea-web | =1.1.6 | |
Redhat Icedtea-web | =1.1.7 | |
Redhat Icedtea-web | =1.2 | |
Redhat Icedtea-web | =1.2.1 | |
Redhat Icedtea-web | =1.3 | |
Redhat Icedtea-web | =1.3.1 | |
Canonical Ubuntu Linux | =10.04 | |
Canonical Ubuntu Linux | =11.10 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =12.10 | |
openSUSE openSUSE | =12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.