First published: Mon Sep 23 2013(Updated: )
LiveConnect provides a gateway between the JavaScript engine in the web browser and Java applets. An insecure temporary file use flaw was found in the LiveConnect implementation in the IcedTea-Web browser plug-in. A malicious, local user could possibly use this flaw to inject or read the communication between a Java applet and web browser of a different user's session. References: <a href="https://jdk6.java.net/plugin2/liveconnect/">https://jdk6.java.net/plugin2/liveconnect/</a> <a href="https://developer.mozilla.org/en-US/docs/Web/JavaScript/Guide/LiveConnect_Overview">https://developer.mozilla.org/en-US/docs/Web/JavaScript/Guide/LiveConnect_Overview</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Icedtea-web | <=1.3.2 | |
Redhat Icedtea-web | =1.0.1 | |
Redhat Icedtea-web | =1.0.2 | |
Redhat Icedtea-web | =1.0.3 | |
Redhat Icedtea-web | =1.0.4 | |
Redhat Icedtea-web | =1.0.5 | |
Redhat Icedtea-web | =1.0.6 | |
Redhat Icedtea-web | =1.1 | |
Redhat Icedtea-web | =1.1.1 | |
Redhat Icedtea-web | =1.1.2 | |
Redhat Icedtea-web | =1.1.3 | |
Redhat Icedtea-web | =1.1.4 | |
Redhat Icedtea-web | =1.1.5 | |
Redhat Icedtea-web | =1.1.6 | |
Redhat Icedtea-web | =1.1.7 | |
Redhat Icedtea-web | =1.2 | |
Redhat Icedtea-web | =1.2.1 | |
Redhat Icedtea-web | =1.2.2 | |
Redhat Icedtea-web | =1.3 | |
Redhat Icedtea-web | =1.3.1 | |
redhat/icedtea-web | <1.4.2 | 1.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.