---
title: "CVE-2013-1926\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2013-1926?format=md
keywords: index, follow
---

# CVE-2013-1926

Publication date 17 April 2013

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same
class loader for applets with the same codebase path but from different
domains, which allows remote attackers to obtain sensitive information or
possibly alter other applets via a crafted applet.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| icedtea-web | 12.10 quantal | Fixed 1.3.2-1ubuntu0.12.10.1 |
| 12.04 LTS precise | Fixed 1.2.3-0ubuntu0.12.04.1 |
| 11.10 oneiric | Fixed 1.2.3-0ubuntu0.11.10.1 |
| 10.04 LTS lucid | Fixed 1.2.3-0ubuntu0.10.04.1 |
| 8.04 LTS hardy | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2013-1926?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| icedtea-web | * Upstream:   <http://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/25dd7c7ac39c> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1926)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2013-1926)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2013-1926)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2013-1926)

### Related Ubuntu Security Notices (USN)

+ [USN-1804-1](https://usn.ubuntu.com/USN-1804-1)
+ IcedTea-Web vulnerabilities
+ 18 April 2013

### Other references

* <http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022790.html>
* <http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022800.html>
* <https://www.cve.org/CVERecord?id=CVE-2013-1926>
