SCIENTIFIC-LINUX-ERRATA Archives

April 2013

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Wed, 17 Apr 2013 20:52:09 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (38 lines)
Synopsis:          Moderate: icedtea-web security update
Advisory ID:       SLSA-2013:0753-1
Issue Date:        2013-04-17
CVE Numbers:       CVE-2013-1927
                   CVE-2013-1926
--

It was discovered that the IcedTea-Web plug-in incorrectly used the same
class loader instance for applets with the same value of the codebase
attribute, even when they originated from different domains. A malicious
applet could use this flaw to gain information about and possibly
manipulate applets from different domains currently running in the
browser. (CVE-2013-1926)

The IcedTea-Web plug-in did not properly check the format of the
downloaded Java Archive (JAR) files. This could cause the plug-in to
execute code hidden in a file in a different format, possibly allowing
attackers to execute code in the context of web sites that allow uploads
of specific file types, known as a GIFAR attack. (CVE-2013-1927)

This erratum also upgrades IcedTea-Web to version 1.2.3.

Web browsers using the IcedTea-Web browser plug-in must be restarted for
this update to take effect.
--

SL6
  x86_64
    icedtea-web-1.2.3-2.el6_4.x86_64.rpm
    icedtea-web-debuginfo-1.2.3-2.el6_4.x86_64.rpm
    icedtea-web-javadoc-1.2.3-2.el6_4.x86_64.rpm
  i386
    icedtea-web-1.2.3-2.el6_4.i686.rpm
    icedtea-web-debuginfo-1.2.3-2.el6_4.i686.rpm
    icedtea-web-javadoc-1.2.3-2.el6_4.i686.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2