CVE-2011-3377
published 2014-02-05CVE-2011-3377: The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute…
PriorityP428medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.22%
80.7th percentile
The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | icedtea-web | < icedtea-web 1.1.4-1 (bookworm) | icedtea-web 1.1.4-1 (bookworm) |
| opensuse | opensuse | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | >= 0 < 1.1.4-1 | 1.1.4-1 |
| redhat | icedtea-web | >= 0 < 1.1.4-1 | 1.1.4-1 |
| redhat | icedtea-web | >= 0 < 1.1.4-1 | 1.1.4-1 |
| redhat | icedtea-web | >= 0 < 1.1.4-1 | 1.1.4-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 6 regression
vendor_ubuntu·2012-01-24·CVSS 4.3
CVE-2011-3389 [MEDIUM] OpenJDK 6 regression
Title: OpenJDK 6 regression
Summary: USN-1263-1 caused a regression when using OpenJDK 6's SSL/TLS
implementation.
USN-1263-1 fixed vulnerabilities in OpenJDK 6. The upstream patch for
the chosen plaintext attack on the block-wise AES encryption algorithm
(CVE-2011-3389) introduced a regression that caused TLS/SSL connections
to fail when using certain algorithms. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Deepak Bhole discovered a flaw in the Same Origin Policy (SOP)
implementation in the IcedTea web browser plugin. This could allow a
remote attacker to open connections to certain hosts that should
not be permitted. (CVE-2011-3377)
Juliano Rizzo and Thai Duong discovered that the block-wise AES
encryption algorithm block-wise as use
Ubuntu
IcedTea-Web, OpenJDK 6 vulnerabilities
vendor_ubuntu·2011-11-16·CVSS 4.3
CVE-2011-3389 [MEDIUM] IcedTea-Web, OpenJDK 6 vulnerabilities
Title: IcedTea-Web, OpenJDK 6 vulnerabilities
Summary: Multiple OpenJDK 6 and IcedTea-Web vulnerabilities have been fixed.
Deepak Bhole discovered a flaw in the Same Origin Policy (SOP)
implementation in the IcedTea web browser plugin. This could allow a
remote attacker to open connections to certain hosts that should
not be permitted. (CVE-2011-3377)
Juliano Rizzo and Thai Duong discovered that the block-wise AES
encryption algorithm block-wise as used in TLS/SSL was vulnerable to
a chosen-plaintext attack. This could allow a remote attacker to view
confidential data. (CVE-2011-3389)
It was discovered that a type confusion flaw existed in the in
the Internet Inter-Orb Protocol (IIOP) deserialization code. A
remote attacker could use this to cause an untrusted application
or applet to
Red Hat
IcedTea-Web: second-level domain subdomains and suffix domain SOP bypass
vendor_redhat·2011-11-08·CVSS 4.3
CVE-2011-3377 [MEDIUM] IcedTea-Web: second-level domain subdomains and suffix domain SOP bypass
IcedTea-Web: second-level domain subdomains and suffix domain SOP bypass
The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2011-3377: icedtea-web - The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4...
vendor_debian·2011·CVSS 4.3
CVE-2011-3377 [MEDIUM] CVE-2011-3377: icedtea-web - The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4...
The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.
Scope: local
bookworm: resolved (fixed in 1.1.4-1)
bullseye: resolved (fixed in 1.1.4-1)
forky: resolved (fixed in 1.1.4-1)
sid: resolved (fixed in 1.1.4-1)
trixie: resolved (fixed in 1.1.4-1)
GHSA
GHSA-cqp6-h2hr-w9xj: The web browser plug-in in IcedTea-Web 1
ghsa_unreviewed·2022-05-14
CVE-2011-3377 [MEDIUM] GHSA-cqp6-h2hr-w9xj: The web browser plug-in in IcedTea-Web 1
The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.
OSV
CVE-2011-3377: The web browser plug-in in IcedTea-Web 1
osv·2014-02-05·CVSS 4.3
CVE-2011-3377 [MEDIUM] CVE-2011-3377: The web browser plug-in in IcedTea-Web 1
The web browser plug-in in IcedTea-Web 1.0.x before 1.0.6 and 1.1.x before 1.1.4 allows remote attackers to bypass the Same Origin Policy (SOP) and execute arbitrary script or establish network connections to unintended hosts via an applet whose origin has the same second-level domain, but a different sub-domain than the targeted domain.
No detection rules found.
No public exploits indexed.
http://dbhole.wordpress.com/2011/11/08/icedtea-web-1-0-6-and-1-1-4-security-releases-released/http://lists.opensuse.org/opensuse-updates/2012-03/msg00028.htmlhttp://rhn.redhat.com/errata/RHSA-2011-1441.htmlhttp://www.debian.org/security/2012/dsa-2420http://www.osvdb.org/76940http://www.securityfocus.com/bid/50610http://www.ubuntu.com/usn/USN-1263-1https://bugzilla.redhat.com/show_bug.cgi?id=742515http://dbhole.wordpress.com/2011/11/08/icedtea-web-1-0-6-and-1-1-4-security-releases-released/http://lists.opensuse.org/opensuse-updates/2012-03/msg00028.htmlhttp://rhn.redhat.com/errata/RHSA-2011-1441.htmlhttp://www.debian.org/security/2012/dsa-2420http://www.osvdb.org/76940http://www.securityfocus.com/bid/50610http://www.ubuntu.com/usn/USN-1263-1https://bugzilla.redhat.com/show_bug.cgi?id=742515
2014-02-05
Published