Oval Definition:oval:com.redhat.rhsa:def:20121434
Revision Date:2012-11-07Version:634
Title:RHSA-2012:1434: icedtea-web security update (Critical)
Description:The IcedTea-Web project provides a Java web browser plug-in and an implementation of Java Web Start, which is based on the Netx project. It also contains a configuration tool for managing deployment settings for the plug-in and Web Start implementations.

  • A buffer overflow flaw was found in the IcedTea-Web plug-in. Visiting a malicious web page could cause a web browser using the IcedTea-Web plug-in to crash or, possibly, execute arbitrary code. (CVE-2012-4540)

    Red Hat would like to thank Arthur Gerkis for reporting this issue.

    This erratum also upgrades IcedTea-Web to version 1.2.2. Refer to the NEWS file, linked to in the References, for further information.

    All IcedTea-Web users should upgrade to these updated packages, which resolve this issue. Web browsers using the IcedTea-Web browser plug-in must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2012-4540
    CVE-2012-4540
    RHSA-2012:1434
    RHSA-2012:1434-01
    RHSA-2012:1434-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • icedtea-web is earlier than 0:1.2.2-1.el6_3
  • AND icedtea-web is signed with Red Hat redhatrelease2 key
  • icedtea-web-javadoc is earlier than 0:1.2.2-1.el6_3
  • AND icedtea-web-javadoc is signed with Red Hat redhatrelease2 key
  • BACK