CVE Vulnerabilities

CVE-2012-4540

Published: Nov 11, 2012 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 CRITICAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.x before 1.4.1 allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly execute arbitrary code via a crafted webpage that triggers a heap-based buffer overflow, related to an error message and a triggering event attached to applet. NOTE: the 1.4.x versions were originally associated with CVE-2013-4349, but that entry has been MERGED with this one.

Affected Software

Name Vendor Start Version End Version
Opensuse Opensuse 13.1 (including) 13.1 (including)
Opensuse Opensuse 13.2 (including) 13.2 (including)
Red Hat Enterprise Linux 6 RedHat icedtea-web-0:1.2.2-1.el6_3 *
Icedtea-web Ubuntu lucid *
Icedtea-web Ubuntu natty *
Icedtea-web Ubuntu oneiric *
Icedtea-web Ubuntu precise *
Icedtea-web Ubuntu quantal *
Icedtea-web Ubuntu upstream *

References