CVE-2012-3423
Summary
| CVE | CVE-2012-3423 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-08-07 21:55:00 UTC |
| Updated | 2014-10-04 04:53:00 UTC |
| Description | The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Icedtea-web | 1.0 | All | All | All |
| Application | Redhat | Icedtea-web | 1.1 | All | All | All |
| Application | Redhat | Icedtea-web | 1.0 | All | All | All |
| Application | Redhat | Icedtea-web | 1.1 | All | All | All |
| Application | Redhat | Icedtea-web | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| USN-1521-1: IcedTea-Web vulnerabilities | Ubuntu | UBUNTU | www.ubuntu.com | |
| Bug 841345 – CVE-2012-3423 icedtea-web: incorrect handling of not 0-terminated strings | MISC | bugzilla.redhat.com | |
| release/icedtea-web-1.2: d65bd94e0ba9 | CONFIRM | icedtea.classpath.org | Exploit, Patch |
| release/icedtea-web-1.2: d7375e2a9076 | CONFIRM | icedtea.classpath.org | Exploit, Patch |
| [security-announce] SUSE-SU-2012:0979-1: important: Security update for | SUSE | lists.opensuse.org | |
| Security Alerts - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| [security-announce] openSUSE-SU-2012:0981-1: important: icedtea-web: Upd | SUSE | lists.opensuse.org | |
| [security-announce] SUSE-SU-2013:0851-1: important: Security update for | SUSE | lists.opensuse.org | |
| Bug 863 – Error passing strings to applet methods in Chromium | CONFIRM | icedtea.classpath.org | Vendor Advisory |
| openSUSE-SU-2013:0966-1: moderate: Package icedtea-web was updated to ve | SUSE | lists.opensuse.org | |
| Gentoo Linux Documentation -- IcedTea JDK: Multiple vulnerabilities | GENTOO | security.gentoo.org | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| release/icedtea-web-1.2: fae550dbc884 NEWS | CONFIRM | icedtea.classpath.org | |
| openSUSE-SU-2013:0826-1: moderate: Package icedtea-web was updated to ve | SUSE | lists.opensuse.org | |
| [security-announce] SUSE-SU-2013:1174-1: important: Security update for | SUSE | lists.opensuse.org | |
| openSUSE-SU-2013:0893-1: moderate: Package icedtea-web was updated to ve | SUSE | lists.opensuse.org | |
| Bug 518 – NPString.utf8characters not guaranteed to be nul-terminated | CONFIRM | icedtea.classpath.org | |
| [security-announce] openSUSE-SU-2012:0982-1: important: update for icedt | SUSE | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.