Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.x before 1.4.1 allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly execute arbitrary code via a crafted webpage that triggers a heap-based buffer overflow, related to an error message and a "triggering event attached to applet." NOTE: the 1.4.x versions were originally associated with CVE-2013-4349, but that entry has been MERGED with this one.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade icedtea-web. | Aug 30, 2017 | Nov 11, 2012 |
| Centos_linux | — | Upgrade icedtea-webUpgrade icedtea-web-javadoc | Dec 1, 2016 | Nov 11, 2012 |
| Debian | — | Upgrade icedtea-web | Jul 30, 2024 | Nov 11, 2012 |
| Gentoo Linux | — | Upgrade dev-java/icedtea-bin. | Oct 30, 2017 | Nov 11, 2012 |
| Oracle_linux | — | Upgrade icedtea-web-javadocUpgrade icedtea-web | Oct 16, 2024 | Nov 11, 2012 |
| Suse | — | Upgrade icedtea-webUpgrade java-1_7_0-openjdk-pluginUpgrade java-1_8_0-openjdk-plugin | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade icedtea-7-pluginUpgrade icedtea-6-plugin | Nov 8, 2024 | Nov 11, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub