CVE-2012-3422
published 2012-08-07CVE-2012-3422: The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.12%
86.4th percentile
The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | icedtea-web | < icedtea-web 1.3-1 (bookworm) | icedtea-web 1.3-1 (bookworm) |
| redhat | icedtea-web | <= 1.2 | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | >= 0 < 1.3-1 | 1.3-1 |
| redhat | icedtea-web | >= 0 < 1.3-1 | 1.3-1 |
| redhat | icedtea-web | >= 0 < 1.3-1 | 1.3-1 |
| redhat | icedtea-web | >= 0 < 1.3-1 | 1.3-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
icedtea-web: getvalueforurl uninitialized instance pointer
vendor_redhat·2012-07-31·CVSS 6.8
CVE-2012-3422 [MEDIUM] icedtea-web: getvalueforurl uninitialized instance pointer
icedtea-web: getvalueforurl uninitialized instance pointer
The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.
Ubuntu
IcedTea-Web vulnerabilities
vendor_ubuntu·2012-07-31·CVSS 6.8
CVE-2012-3422 [MEDIUM] IcedTea-Web vulnerabilities
Title: IcedTea-Web vulnerabilities
Summary: The IcedTea-Web Java web browser plugin could be made to crash or
possibly run programs as your login if it opened a specially crafted
applet.
Chamal De Silva discovered that the IcedTea-Web Java web browser
plugin could dereference an uninitialized pointer. A remote attacker
could use this to craft a malicious web page that could cause a
denial of service by crashing the web browser or possibly execute
arbitrary code. (CVE-2012-3422)
Steven Bergom and others discovered that the IcedTea-Web Java web
browser plugin assumed that all strings provided by browsers are NULL
terminated, which is not guaranteed by the NPAPI (Netscape Plugin
Application Programming Interface). A remote attacker could use this
to craft a malicious Java applet that could
Debian
CVE-2012-3422: icedtea-web - The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 retu...
vendor_debian·2012·CVSS 6.8
CVE-2012-3422 [MEDIUM] CVE-2012-3422: icedtea-web - The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 retu...
The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.
Scope: local
bookworm: resolved (fixed in 1.3-1)
bullseye: resolved (fixed in 1.3-1)
forky: resolved (fixed in 1.3-1)
sid: resolved (fixed in 1.3-1)
trixie: resolved (fixed in 1.3-1)
GHSA
GHSA-qwm3-gpj3-x6c9: The getFirstInTableInstance function in the IcedTea-Web plugin before 1
ghsa_unreviewed·2022-05-17
CVE-2012-3422 [MEDIUM] CWE-119 GHSA-qwm3-gpj3-x6c9: The getFirstInTableInstance function in the IcedTea-Web plugin before 1
The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.
OSV
CVE-2012-3422: The getFirstInTableInstance function in the IcedTea-Web plugin before 1
osv·2012-08-07·CVSS 6.8
CVE-2012-3422 [MEDIUM] CVE-2012-3422: The getFirstInTableInstance function in the IcedTea-Web plugin before 1
The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3422 CVE-2012-3423 icedtea-web various flaws [fedora-all]
bugzilla·2012-07-31·CVSS 6.8
CVE-2012-3422 [MEDIUM] CVE-2012-3422 CVE-2012-3423 icedtea-web various flaws [fedora-all]
CVE-2012-3422 CVE-2012-3423 icedtea-web various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=840
Bugzilla
CVE-2012-3422 icedtea-web: getvalueforurl uninitialized instance pointer
bugzilla·2012-07-16·CVSS 6.8
CVE-2012-3422 [MEDIUM] CVE-2012-3422 icedtea-web: getvalueforurl uninitialized instance pointer
CVE-2012-3422 icedtea-web: getvalueforurl uninitialized instance pointer
An uninitialized pointer use flaw was found in IcedTea-Web web browser plugin. A malicious web page could use this flaw make IcedTea-Web browser plugin pass invalid pointer to a web browser. Depending on the browser used, it may cause the browser to crash or possibly execute arbitrary code.
The get_cookie_info() and get_proxy_info() call getFirstInTableInstance() with the instance_to_id_map hash as a parameter. If instance_to_id_map is empty (which can happen when plugin was recently removed), getFirstInTableInstance() returns an uninitialized pointer.
http://icedtea.classpath.org/hg/icedtea-web/file/01544fb82384/plugin/icedteanp/IcedTeaNPPlugin.cc#l292
Discussion:
Created attachment 598511
Fix for 1.1/1.2/1.3/HE
http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.1/NEWShttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00032.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00101.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1132.htmlhttp://secunia.com/advisories/50089http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.ubuntu.com/usn/USN-1521-1https://bugzilla.redhat.com/show_bug.cgi?id=840592http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.1/NEWShttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00032.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00101.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1132.htmlhttp://secunia.com/advisories/50089http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.ubuntu.com/usn/USN-1521-1https://bugzilla.redhat.com/show_bug.cgi?id=840592
2012-08-07
Published