CVE-2013-1926

The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets via a crafted applet.
References
Link Resource
http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.3/NEWS
http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/34b6f60ae586
http://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/25dd7c7ac39c
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00013.html
http://lists.opensuse.org/opensuse-updates/2013-04/msg00106.html
http://lists.opensuse.org/opensuse-updates/2013-05/msg00003.html
http://lists.opensuse.org/opensuse-updates/2013-05/msg00032.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00030.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00034.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00101.html
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022790.html
http://osvdb.org/92543
http://rhn.redhat.com/errata/RHSA-2013-0753.html
http://secunia.com/advisories/53109 Vendor Advisory
http://secunia.com/advisories/53117 Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2013:146
http://www.securityfocus.com/bid/59281
http://www.ubuntu.com/usn/USN-1804-1
https://bugzilla.redhat.com/show_bug.cgi?id=916774
https://exchange.xforce.ibmcloud.com/vulnerabilities/83642
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0123
http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.3/NEWS
http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/34b6f60ae586
http://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/25dd7c7ac39c
http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00013.html
http://lists.opensuse.org/opensuse-updates/2013-04/msg00106.html
http://lists.opensuse.org/opensuse-updates/2013-05/msg00003.html
http://lists.opensuse.org/opensuse-updates/2013-05/msg00032.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00030.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00034.html
http://lists.opensuse.org/opensuse-updates/2013-06/msg00101.html
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022790.html
http://osvdb.org/92543
http://rhn.redhat.com/errata/RHSA-2013-0753.html
http://secunia.com/advisories/53109 Vendor Advisory
http://secunia.com/advisories/53117 Vendor Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2013:146
http://www.securityfocus.com/bid/59281
http://www.ubuntu.com/usn/USN-1804-1
https://bugzilla.redhat.com/show_bug.cgi?id=916774
https://exchange.xforce.ibmcloud.com/vulnerabilities/83642
https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0123
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:icedtea-web:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.1.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.1.5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.1.6:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.1.7:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea-web:1.3.1:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:*

History

21 Nov 2024, 01:50

Type Values Removed Values Added
References () http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.3/NEWS - () http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.3/NEWS -
References () http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/34b6f60ae586 - () http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/34b6f60ae586 -
References () http://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/25dd7c7ac39c - () http://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/25dd7c7ac39c -
References () http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.html - () http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.html -
References () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00013.html - () http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00013.html -
References () http://lists.opensuse.org/opensuse-updates/2013-04/msg00106.html - () http://lists.opensuse.org/opensuse-updates/2013-04/msg00106.html -
References () http://lists.opensuse.org/opensuse-updates/2013-05/msg00003.html - () http://lists.opensuse.org/opensuse-updates/2013-05/msg00003.html -
References () http://lists.opensuse.org/opensuse-updates/2013-05/msg00032.html - () http://lists.opensuse.org/opensuse-updates/2013-05/msg00032.html -
References () http://lists.opensuse.org/opensuse-updates/2013-06/msg00030.html - () http://lists.opensuse.org/opensuse-updates/2013-06/msg00030.html -
References () http://lists.opensuse.org/opensuse-updates/2013-06/msg00034.html - () http://lists.opensuse.org/opensuse-updates/2013-06/msg00034.html -
References () http://lists.opensuse.org/opensuse-updates/2013-06/msg00101.html - () http://lists.opensuse.org/opensuse-updates/2013-06/msg00101.html -
References () http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022790.html - () http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022790.html -
References () http://osvdb.org/92543 - () http://osvdb.org/92543 -
References () http://rhn.redhat.com/errata/RHSA-2013-0753.html - () http://rhn.redhat.com/errata/RHSA-2013-0753.html -
References () http://secunia.com/advisories/53109 - Vendor Advisory () http://secunia.com/advisories/53109 - Vendor Advisory
References () http://secunia.com/advisories/53117 - Vendor Advisory () http://secunia.com/advisories/53117 - Vendor Advisory
References () http://www.mandriva.com/security/advisories?name=MDVSA-2013:146 - () http://www.mandriva.com/security/advisories?name=MDVSA-2013:146 -
References () http://www.securityfocus.com/bid/59281 - () http://www.securityfocus.com/bid/59281 -
References () http://www.ubuntu.com/usn/USN-1804-1 - () http://www.ubuntu.com/usn/USN-1804-1 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=916774 - () https://bugzilla.redhat.com/show_bug.cgi?id=916774 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/83642 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/83642 -
References () https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0123 - () https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0123 -

Information

Published : 2013-04-29 22:55

Updated : 2024-11-21 01:50


NVD link : CVE-2013-1926

Mitre link : CVE-2013-1926

CVE.ORG link : CVE-2013-1926


JSON object : View

Products Affected

redhat

  • icedtea-web

canonical

  • ubuntu_linux

opensuse

  • opensuse