Revision Date: | 2014-06-23 | Version: | 6 |
Title: | DSA-2768-1 icedtea-web - heap-based buffer overflow |
Description: | A heap-based buffer overflow vulnerability was found in icedtea-web, a web browser plugin for running applets written in the Java programming language. If a user were tricked into opening a malicious website, an attacker could cause the plugin to crash or possibly execute arbitrary code as the user invoking the program. |
Family: | unix | Class: | patch |
Status: | ACCEPTED | Reference(s): | CVE-2012-4540 CVE-2013-4349 DSA-2768-1
|
Platform(s): | Debian GNU/kFreeBSD 7 Debian GNU/Linux 7
| Product(s): | icedtea-web
|
Definition Synopsis |
Debian 7 is installed AND GNU/Linux or GNU/kFreeBSD kernel
Debian GNU/Linux is installed
OR Debian GNU/kFreeBSD is installed
AND icedtea-web DPKG is earlier than 0:1.4-3~deb7u2
|