CVE-2012-3423
published 2012-08-07CVE-2012-3423: The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of…
PriorityP343high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.17%
92.7th percentile
The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | icedtea-web | < icedtea-web 1.3-1 (bookworm) | icedtea-web 1.3-1 (bookworm) |
| redhat | icedtea-web | <= 1.2 | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | >= 0 < 1.3-1 | 1.3-1 |
| redhat | icedtea-web | >= 0 < 1.3-1 | 1.3-1 |
| redhat | icedtea-web | >= 0 < 1.3-1 | 1.3-1 |
| redhat | icedtea-web | >= 0 < 1.3-1 | 1.3-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
icedtea-web: incorrect handling of not 0-terminated strings
vendor_redhat·2012-07-31·CVSS 7.5
CVE-2012-3423 [HIGH] icedtea-web: incorrect handling of not 0-terminated strings
icedtea-web: incorrect handling of not 0-terminated strings
The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.
Ubuntu
IcedTea-Web vulnerabilities
vendor_ubuntu·2012-07-31·CVSS 6.8
CVE-2012-3422 [MEDIUM] IcedTea-Web vulnerabilities
Title: IcedTea-Web vulnerabilities
Summary: The IcedTea-Web Java web browser plugin could be made to crash or
possibly run programs as your login if it opened a specially crafted
applet.
Chamal De Silva discovered that the IcedTea-Web Java web browser
plugin could dereference an uninitialized pointer. A remote attacker
could use this to craft a malicious web page that could cause a
denial of service by crashing the web browser or possibly execute
arbitrary code. (CVE-2012-3422)
Steven Bergom and others discovered that the IcedTea-Web Java web
browser plugin assumed that all strings provided by browsers are NULL
terminated, which is not guaranteed by the NPAPI (Netscape Plugin
Application Programming Interface). A remote attacker could use this
to craft a malicious Java applet that could
Debian
CVE-2012-3423: icedtea-web - The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings...
vendor_debian·2012·CVSS 7.5
CVE-2012-3423 [HIGH] CVE-2012-3423: icedtea-web - The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings...
The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.
Scope: local
bookworm: resolved (fixed in 1.3-1)
bullseye: resolved (fixed in 1.3-1)
forky: resolved (fixed in 1.3-1)
sid: resolved (fixed in 1.3-1)
trixie: resolved (fixed in 1.3-1)
GHSA
GHSA-wg7g-m9g6-qcmw: The IcedTea-Web plugin before 1
ghsa_unreviewed·2022-05-17
CVE-2012-3423 [HIGH] CWE-119 GHSA-wg7g-m9g6-qcmw: The IcedTea-Web plugin before 1
The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.
OSV
CVE-2012-3423: The IcedTea-Web plugin before 1
osv·2012-08-07·CVSS 7.5
CVE-2012-3423 [HIGH] CVE-2012-3423: The IcedTea-Web plugin before 1
The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3422 CVE-2012-3423 icedtea-web various flaws [fedora-all]
bugzilla·2012-07-31·CVSS 6.8
CVE-2012-3422 [MEDIUM] CVE-2012-3422 CVE-2012-3423 icedtea-web various flaws [fedora-all]
CVE-2012-3422 CVE-2012-3423 icedtea-web various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=840
Bugzilla
CVE-2012-3423 icedtea-web: incorrect handling of not 0-terminated strings
bugzilla·2012-07-18·CVSS 7.5
CVE-2012-3423 [HIGH] CVE-2012-3423 icedtea-web: incorrect handling of not 0-terminated strings
CVE-2012-3423 icedtea-web: incorrect handling of not 0-terminated strings
It was discovered that the IcedTea-Web web browser plugin incorrectly assumed that all strings provided by browser are NUL terminated, which is not guaranteed by the NPAPI (Netscape Plugin Application Programming Interface). When used in a browser that does not NUL terminate NPVariant NPStrings, this could lead to buffer over-read or over-write, resulting in possible information leak, crash, or code execution.
Mozilla browsers currently NUL terminate strings, however recent Chrome versions are known not to provide NUL terminated data.
Related upstream bug reports and commits:
http://icedtea.classpath.org/bugzilla/show_bug.cgi?id=518
http://icedtea.classpath.org/bugzilla/show_bug.cgi?id=863
http://icedtea.classpath
http://icedtea.classpath.org/bugzilla/show_bug.cgi?id=518http://icedtea.classpath.org/bugzilla/show_bug.cgi?id=863http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.1/NEWShttp://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/d65bd94e0ba9http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/d7375e2a9076http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00032.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00101.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1132.htmlhttp://secunia.com/advisories/50089http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.ubuntu.com/usn/USN-1521-1https://bugzilla.redhat.com/show_bug.cgi?id=841345http://icedtea.classpath.org/bugzilla/show_bug.cgi?id=518http://icedtea.classpath.org/bugzilla/show_bug.cgi?id=863http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.1/NEWShttp://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/d65bd94e0ba9http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/d7375e2a9076http://lists.opensuse.org/opensuse-security-announce/2012-08/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-08/msg00005.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00032.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00101.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1132.htmlhttp://secunia.com/advisories/50089http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.ubuntu.com/usn/USN-1521-1https://bugzilla.redhat.com/show_bug.cgi?id=841345
2012-08-07
Published