Synopsis: Moderate: icedtea-web security update
Advisory ID: SLSA-2013:0753-1
Issue Date: 2013-04-17
CVE Numbers: CVE-2013-1927
CVE-2013-1926
—
It was discovered that the IcedTea-Web plug-in incorrectly used the same
class loader instance for applets with the same value of the codebase
attribute, even when they originated from different domains. A malicious
applet could use this flaw to gain information about and possibly
manipulate applets from different domains currently running in the
browser. (CVE-2013-1926)
The IcedTea-Web plug-in did not properly check the format of the
downloaded Java Archive (JAR) files. This could cause the plug-in to
execute code hidden in a file in a different format, possibly allowing
attackers to execute code in the context of web sites that allow uploads
of specific file types, known as a GIFAR attack. (CVE-2013-1927)
This erratum also upgrades IcedTea-Web to version 1.2.3.
Web browsers using the IcedTea-Web browser plug-in must be restarted for
this update to take effect.
—
SL6
x86_64
icedtea-web-1.2.3-2.el6_4.x86_64.rpm
icedtea-web-debuginfo-1.2.3-2.el6_4.x86_64.rpm
icedtea-web-javadoc-1.2.3-2.el6_4.x86_64.rpm
i386
icedtea-web-1.2.3-2.el6_4.i686.rpm
icedtea-web-debuginfo-1.2.3-2.el6_4.i686.rpm
icedtea-web-javadoc-1.2.3-2.el6_4.i686.rpm
– Scientific Linux Development Team