IcedTea-Web Multiple Arbitrary Code Execution Vulnerabilities
BID:54762
Info
IcedTea-Web Multiple Arbitrary Code Execution Vulnerabilities
| Bugtraq ID: | 54762 |
| Class: | Design Error |
| CVE: |
CVE-2012-3422 CVE-2012-3423 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 31 2012 12:00AM |
| Updated: | Apr 16 2015 06:13PM |
| Credit: | Reported by vendor. |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 SuSE SUSE Linux Enterprise Desktop 11 SP2 SuSE SUSE Linux Enterprise Desktop 11 SP1 SuSE openSUSE 12.1 SuSE openSUSE 11.4 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Mandriva Linux Mandrake 2011 x86_64 Mandriva Linux Mandrake 2011 MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 Gentoo Linux |
| Not Vulnerable: | |
Discussion
IcedTea-Web Multiple Arbitrary Code Execution Vulnerabilities
IcedTea-Web is prone to multiple arbitrary code-execution vulnerabilities.
Successful exploits may allow attackers to execute arbitrary code in the context of the affected application or to trigger denial-of-service conditions. Other attacks may also be possible.
IcedTea-Web is prone to multiple arbitrary code-execution vulnerabilities.
Successful exploits may allow attackers to execute arbitrary code in the context of the affected application or to trigger denial-of-service conditions. Other attacks may also be possible.
Exploit / POC
IcedTea-Web Multiple Arbitrary Code Execution Vulnerabilities
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IcedTea-Web Multiple Arbitrary Code Execution Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Mandriva Linux Mandrake 2011 x86_64
Mandriva Linux Mandrake 2011
Solution:
Updates are available. Please see the references for more information.
MandrakeSoft Enterprise Server 5 x86_64
-
Mandriva icedtea-web-1.1.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva icedtea-web-javadoc-1.1.6-0.1mdvmes5.2.x86_64.rpm
http://www.mandriva.com/en/downloads/
MandrakeSoft Enterprise Server 5
-
Mandriva icedtea-web-1.1.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva icedtea-web-javadoc-1.1.6-0.1mdvmes5.2.i586.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011 x86_64
-
Mandriva icedtea-web-1.1.6-0.1-mdv2011.0.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva icedtea-web-javadoc-1.1.6-0.1-mdv2011.0.noarch.rpm
http://www.mandriva.com/en/downloads/
Mandriva Linux Mandrake 2011
-
Mandriva icedtea-web-1.1.6-0.1-mdv2011.0.i586.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva icedtea-web-javadoc-1.1.6-0.1-mdv2011.0.noarch.rpm
http://www.mandriva.com/en/downloads/
References
IcedTea-Web Multiple Arbitrary Code Execution Vulnerabilities
References:
References:
- Bug 840592 - (CVE-2012-3422) CVE-2012-3422 icedtea-web: getvalueforurl uninitial (Red Hat Bugzilla)
- Bug 841345 - (CVE-2012-3423) CVE-2012-3423 icedtea-web: incorrect handling of no (Red Hat Bugzilla)
- release - icedtea-web-1.2.1 (IcedTea)