CVE-2012-4540

Severity
6.8MEDIUM
EPSS
1.5%
top 18.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 11
Latest updateMay 14

Description

Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.x before 1.4.1 allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly execute arbitrary code via a crafted webpage that triggers a heap-based buffer overflow, related to an error message and a "triggering event attached to applet." NOTE: the 1.4.x versions were originally associated with CVE

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages3 packages

Debianicedtea-web< 1.3.1-1+3
NVDredhat/icedtea-web10 versions+9
NVDopensuse/opensuse13.1, 13.2+1

🔴Vulnerability Details

3
GHSA
GHSA-44v2-cg42-mx34: Off-by-one error in the invoke function in IcedTeaScriptablePluginObject2022-05-14
CVEList
CVE-2012-4540: Off-by-one error in the invoke function in IcedTeaScriptablePluginObject2012-11-11
OSV
CVE-2012-4540: Off-by-one error in the invoke function in IcedTeaScriptablePluginObject2012-11-11

📋Vendor Advisories

4
Red Hat
icedtea-web: issue not fixed in 1.42013-09-16
Red Hat
icedtea-web: IcedTeaScriptableJavaObject:: invoke off-by-one heap-based buffer overflow2012-11-07
Ubuntu
Icedtea-Web vulnerability2012-11-07
Debian
CVE-2012-4540: icedtea-web - Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in I...2012

💬Community

3
Bugzilla
CVE-2013-4349 icedtea-web: CVE-2012-4540 issue not fixed in 1.4 [fedora-all]2013-09-16
Bugzilla
CVE-2013-4349 icedtea-web: CVE-2012-4540 issue not fixed in 1.42013-09-13
Bugzilla
CVE-2012-4540 icedtea-web: IcedTeaScriptableJavaObject::invoke off-by-one heap-based buffer overflow2012-10-22
CVE-2012-4540 (MEDIUM CVSS 6.8) | Off-by-one error in the invoke func | cvebase.io