CVE-2012-4540
published 2012-11-11CVE-2012-4540: Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and…
PriorityP434medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.44%
87.6th percentile
Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.x before 1.4.1 allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly execute arbitrary code via a crafted webpage that triggers a heap-based buffer overflow, related to an error message and a "triggering event attached to applet." NOTE: the 1.4.x versions were originally associated with CVE-2013-4349, but that entry has been MERGED with this one.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | icedtea-web | < icedtea-web 1.3.1-1 (bookworm) | icedtea-web 1.3.1-1 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | >= 0 < 1.3.1-1 | 1.3.1-1 |
| redhat | icedtea-web | >= 0 < 1.3.1-1 | 1.3.1-1 |
| redhat | icedtea-web | >= 0 < 1.3.1-1 | 1.3.1-1 |
| redhat | icedtea-web | >= 0 < 1.3.1-1 | 1.3.1-1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
icedtea-web: issue not fixed in 1.4
vendor_redhat·2013-09-16·CVSS 6.8
CVE-2013-4349 [MEDIUM] icedtea-web: issue not fixed in 1.4
icedtea-web: issue not fixed in 1.4
No description is available for this CVE.
Statement: Not vulnerable. This issue did not affect the versions of icedtea-web as shipped with Red Hat Enterprise Linux 6. The CVE-2012-4540 issue was previously corrected via RHSA-2012:1434.
Package: icedtea-web (Red Hat Enterprise Linux 6) - Not affected
Package: icedtea-web (Red Hat Enterprise Linux 7) - Not affected
Red Hat
icedtea-web: IcedTeaScriptableJavaObject:: invoke off-by-one heap-based buffer overflow
vendor_redhat·2012-11-07·CVSS 6.8
CVE-2012-4540 [MEDIUM] CWE-122 icedtea-web: IcedTeaScriptableJavaObject:: invoke off-by-one heap-based buffer overflow
icedtea-web: IcedTeaScriptableJavaObject:: invoke off-by-one heap-based buffer overflow
Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.x before 1.4.1 allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly execute arbitrary code via a crafted webpage that triggers a heap-based buffer overflow, related to an error message and a "triggering event attached to applet." NOTE: the 1.4.x versions were originally associated with CVE-2013-4349, but that entry has been MERGED with this one.
Ubuntu
Icedtea-Web vulnerability
vendor_ubuntu·2012-11-07
CVE-2012-4540 Icedtea-Web vulnerability
Title: Icedtea-Web vulnerability
Summary: The Icedtea-Web plugin could be made to crash or run programs as your login
if it opened a specially crafted web page.
Arthur Gerkis discovered a buffer overflow in the Icedtea-Web plugin. If a
user were tricked into opening a malicious website, an attacker could
cause the plugin to crash or possibly execute arbitrary code as the user
invoking the program.
Instructions: After a standard system update you need to restart your browser to make
all the necessary changes.
Debian
CVE-2012-4540: icedtea-web - Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in I...
vendor_debian·2012·CVSS 6.8
CVE-2012-4540 [MEDIUM] CVE-2012-4540: icedtea-web - Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in I...
Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.x before 1.4.1 allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly execute arbitrary code via a crafted webpage that triggers a heap-based buffer overflow, related to an error message and a "triggering event attached to applet." NOTE: the 1.4.x versions were originally associated with CVE-2013-4349, but that entry has been MERGED with this one.
Scope: local
bookworm: resolved (fixed in 1.3.1-1)
bullseye: resolved (fixed in 1.3.1-1)
forky: resolved (fixed in 1.3.1-1)
sid: resolved (fixed in 1.3.1-1)
trixie: resolved (fixed in 1.3.1-1)
GHSA
GHSA-44v2-cg42-mx34: Off-by-one error in the invoke function in IcedTeaScriptablePluginObject
ghsa_unreviewed·2022-05-14·CVSS 6.8
CVE-2012-4540 [MEDIUM] GHSA-44v2-cg42-mx34: Off-by-one error in the invoke function in IcedTeaScriptablePluginObject
Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.x before 1.4.1 allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly execute arbitrary code via a crafted webpage that triggers a heap-based buffer overflow, related to an error message and a "triggering event attached to applet." NOTE: the 1.4.x versions were originally associated with CVE-2013-4349, but that entry has been MERGED with this one.
OSV
CVE-2012-4540: Off-by-one error in the invoke function in IcedTeaScriptablePluginObject
osv·2012-11-11·CVSS 6.8
CVE-2012-4540 [MEDIUM] CVE-2012-4540: Off-by-one error in the invoke function in IcedTeaScriptablePluginObject
Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.x before 1.4.1 allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly execute arbitrary code via a crafted webpage that triggers a heap-based buffer overflow, related to an error message and a "triggering event attached to applet." NOTE: the 1.4.x versions were originally associated with CVE-2013-4349, but that entry has been MERGED with this one.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4349 icedtea-web: CVE-2012-4540 issue not fixed in 1.4 [fedora-all]
bugzilla·2013-09-16·CVSS 6.8
CVE-2013-4349 [MEDIUM] CVE-2013-4349 icedtea-web: CVE-2012-4540 issue not fixed in 1.4 [fedora-all]
CVE-2013-4349 icedtea-web: CVE-2012-4540 issue not fixed in 1.4 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affe
Bugzilla
CVE-2013-4349 icedtea-web: CVE-2012-4540 issue not fixed in 1.4
bugzilla·2013-09-13·CVSS 6.8
CVE-2013-4349 [MEDIUM] CVE-2013-4349 icedtea-web: CVE-2012-4540 issue not fixed in 1.4
CVE-2013-4349 icedtea-web: CVE-2012-4540 issue not fixed in 1.4
An off-by-one heap-based buffer overflow was found in IcedTeaScriptableJavaObject::invoke function. This problem was discovered in Oct 2012 and was assigned CVE-2012-4540. For more detailed description, refer to bug 869040 comment 5.
The patch for this issue was applied to 1.1, 1.2, and 1.3 IcedTea-Web branches, see bug 869040 comment 10. However, the fix did not get applied to head. Version 1.4 released in May 2013 did not include the fix and is affected by the issue.
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-May/023195.html
A new CVE id CVE-2013-4349 was assigned for the missing fix in 1.4.
Discussion:
Statement:
Not vulnerable. This issue did not affect the versions of icedtea-web as shipped with Red
Bugzilla
CVE-2012-4540 icedtea-web: IcedTeaScriptableJavaObject::invoke off-by-one heap-based buffer overflow
bugzilla·2012-10-22·CVSS 6.8
CVE-2012-4540 [MEDIUM] CVE-2012-4540 icedtea-web: IcedTeaScriptableJavaObject::invoke off-by-one heap-based buffer overflow
CVE-2012-4540 icedtea-web: IcedTeaScriptableJavaObject::invoke off-by-one heap-based buffer overflow
A flaw was reported in IcedTea-web plugin where certain events attached to an applet, when triggered, could lead to a heap-based buffer overflow, resulting in possible information leak, crash, or code execution.
Discussion:
This has been assigned CVE-2012-4540.
---
Created attachment 631741
proposed patch
---
Created attachment 635041
Update patch from Deepak Bhole
---
(In reply to comment #0)
> A flaw was reported in IcedTea-web plugin where certain events attached to
> an applet, when triggered, could lead to a heap-based buffer overflow,
> resulting in possible information leak, crash, or code execution.
The problem is in the IcedTeaScriptableJavaObject::invoke function:
http:
http://icedtea.classpath.org/hg/release/icedtea-web-1.1/file/d759ec560073/NEWShttp://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/596a718be03fhttp://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/e7970f3da5fehttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00019.htmlhttp://lists.opensuse.org/opensuse-updates/2012-11/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00065.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00071.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00073.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-November/020775.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-September/024750.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1434.htmlhttp://secunia.com/advisories/51206http://secunia.com/advisories/51220http://secunia.com/advisories/51374http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.debian.org/security/2013/dsa-2768http://www.mandriva.com/security/advisories?name=MDVSA-2012:171http://www.openwall.com/lists/oss-security/2012/11/07/5http://www.securityfocus.com/bid/56434http://www.securityfocus.com/bid/62426http://www.securitytracker.com/id?1027738http://www.ubuntu.com/usn/USN-1625-1https://bugzilla.redhat.com/show_bug.cgi?id=1007960https://bugzilla.redhat.com/show_bug.cgi?id=869040https://exchange.xforce.ibmcloud.com/vulnerabilities/79894http://icedtea.classpath.org/hg/release/icedtea-web-1.1/file/d759ec560073/NEWShttp://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/596a718be03fhttp://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/e7970f3da5fehttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00019.htmlhttp://lists.opensuse.org/opensuse-updates/2012-11/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2013-01/msg00065.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00071.htmlhttp://lists.opensuse.org/opensuse-updates/2013-09/msg00073.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-November/020775.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-September/024750.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1434.htmlhttp://secunia.com/advisories/51206http://secunia.com/advisories/51220http://secunia.com/advisories/51374http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.debian.org/security/2013/dsa-2768http://www.mandriva.com/security/advisories?name=MDVSA-2012:171http://www.openwall.com/lists/oss-security/2012/11/07/5http://www.securityfocus.com/bid/56434http://www.securityfocus.com/bid/62426http://www.securitytracker.com/id?1027738http://www.ubuntu.com/usn/USN-1625-1https://bugzilla.redhat.com/show_bug.cgi?id=1007960https://bugzilla.redhat.com/show_bug.cgi?id=869040https://exchange.xforce.ibmcloud.com/vulnerabilities/79894
2012-11-11
Published