CVE-2013-6493
Published: 3 March 2014
The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugin.cc in IcedTea-Web before 1.4.2 allows local users to read the messages between a Java applet and a web browser by pre-creating a temporary socket file with a predictable name in /tmp.
Priority
Status
Package | Release | Status |
---|---|---|
icedtea-web Launchpad, Ubuntu, Debian |
lucid |
Ignored
(end of life)
|
precise |
Released
(1.2.3-0ubuntu0.12.04.4)
|
|
quantal |
Released
(1.3.2-1ubuntu0.12.10.3)
|
|
saucy |
Released
(1.4-3ubuntu2.1)
|
|
upstream |
Released
(1.4.2-1)
|
|
Patches: upstream: http://icedtea.classpath.org/hg/icedtea-web/rev/228e3652214a upstream: http://icedtea.classpath.org/hg/icedtea-web/rev/1e0507976663 upstream: http://icedtea.classpath.org/hg/release/icedtea-web-1.4/rev/35f4d27451fd upstream: http://icedtea.classpath.org/hg/release/icedtea-web-1.4/rev/1ae3613c82f2 |