[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2012-4540Date: (C)2012-11-12   (M)2023-12-22


Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.x before 1.4.1 allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly execute arbitrary code via a crafted webpage that triggers a heap-based buffer overflow, related to an error message and a "triggering event attached to applet." NOTE: the 1.4.x versions were originally associated with CVE-2013-4349, but that entry has been MERGED with this one.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1027738
SECUNIA-51206
SECUNIA-51220
SECUNIA-51374
BID-56434
BID-62426
DSA-2768
GLSA-201406-32
MDVSA-2012:171
RHSA-2012:1434
USN-1625-1
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-November/020775.html
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-September/024750.html
http://www.openwall.com/lists/oss-security/2012/11/07/5
http://icedtea.classpath.org/hg/release/icedtea-web-1.1/file/d759ec560073/NEWS
http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/596a718be03f
http://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/e7970f3da5fe
https://bugzilla.redhat.com/show_bug.cgi?id=1007960
https://bugzilla.redhat.com/show_bug.cgi?id=869040
icedtea-applet-bo(79894)
openSUSE-SU-2012:1524
openSUSE-SU-2013:0174
openSUSE-SU-2013:1509
openSUSE-SU-2013:1511
openSUSE-SU-2015:1595

CPE    11
cpe:/o:opensuse:opensuse:13.1
cpe:/a:redhat:icedtea-web:1.3
cpe:/a:redhat:icedtea-web:1.1
cpe:/a:redhat:icedtea-web:1.2
...
CWE    1
CWE-189
OVAL    11
oval:org.secpod.oval:def:701064
oval:org.secpod.oval:def:104305
oval:org.secpod.oval:def:104850
oval:org.secpod.oval:def:104300
...

© SecPod Technologies