CVE-2013-1926
published 2013-04-29CVE-2013-1926: The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which…
PriorityP422medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.86%
76.9th percentile
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets via a crafted applet.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | icedtea-web | < icedtea-web 1.3.2-1 (bookworm) | icedtea-web 1.3.2-1 (bookworm) |
| opensuse | opensuse | — | — |
| redhat | icedtea-web | <= 1.2.2 | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
IcedTea-Web regression
vendor_ubuntu·2013-04-23·CVSS 5.8
[MEDIUM] IcedTea-Web regression
Title: IcedTea-Web regression
Summary: Due to a regression, IcedTea-Web might not be able to access some sites.
USN-1804-1 fixed vulnerabilities in IcedTea-Web. This update introduced
a regression with the Java Network Launching Protocol (JNLP) when fetching
content over SSL under certain configurations, such as when using the
community-supported IcedTead 7 browser plugin. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Jiri Vanek discovered that IcedTea-Web would use the same classloader for
applets from different domains. A remote attacker could exploit this to
expose sensitive information or potentially manipulate applets from other
domains. (CVE-2013-1926)
It was discovered that IcedTea-Web did not properly verify JAR files and
was su
Ubuntu
IcedTea-Web vulnerabilities
vendor_ubuntu·2013-04-18·CVSS 5.8
CVE-2013-1926 [MEDIUM] IcedTea-Web vulnerabilities
Title: IcedTea-Web vulnerabilities
Summary: Two security issues were fixed in IcedTea-Web.
Jiri Vanek discovered that IcedTea-Web would use the same classloader for
applets from different domains. A remote attacker could exploit this to
expose sensitive information or potentially manipulate applets from other
domains. (CVE-2013-1926)
It was discovered that IcedTea-Web did not properly verify JAR files and
was susceptible to the GIFAR attack. If a user were tricked into opening a
malicious website, a remote attacker could potentially exploit this to
execute code under certain circumstances. (CVE-2013-1927)
Instructions: After a standard system update you need to restart your browser to make
all the necessary changes.
Red Hat
icedtea-web: class loader sharing for applets with same codebase paths
vendor_redhat·2013-04-17·CVSS 5.8
CVE-2013-1926 [MEDIUM] icedtea-web: class loader sharing for applets with same codebase paths
icedtea-web: class loader sharing for applets with same codebase paths
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets via a crafted applet.
Debian
CVE-2013-1926: icedtea-web - The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class l...
vendor_debian·2013·CVSS 5.8
CVE-2013-1926 [MEDIUM] CVE-2013-1926: icedtea-web - The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class l...
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets via a crafted applet.
Scope: local
bookworm: resolved (fixed in 1.3.2-1)
bullseye: resolved (fixed in 1.3.2-1)
forky: resolved (fixed in 1.3.2-1)
sid: resolved (fixed in 1.3.2-1)
trixie: resolved (fixed in 1.3.2-1)
GHSA
GHSA-vwgw-5wg9-mw8j: The IcedTea-Web plugin before 1
ghsa_unreviewed·2022-05-14
CVE-2013-1926 [MEDIUM] GHSA-vwgw-5wg9-mw8j: The IcedTea-Web plugin before 1
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets via a crafted applet.
OSV
CVE-2013-1926: The IcedTea-Web plugin before 1
osv·2013-04-29·CVSS 5.8
CVE-2013-1926 [MEDIUM] CVE-2013-1926: The IcedTea-Web plugin before 1
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets via a crafted applet.
No detection rules found.
No public exploits indexed.
http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.3/NEWShttp://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/34b6f60ae586http://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/25dd7c7ac39chttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00106.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00032.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00034.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00101.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022790.htmlhttp://osvdb.org/92543http://rhn.redhat.com/errata/RHSA-2013-0753.htmlhttp://secunia.com/advisories/53109http://secunia.com/advisories/53117http://www.mandriva.com/security/advisories?name=MDVSA-2013:146http://www.securityfocus.com/bid/59281http://www.ubuntu.com/usn/USN-1804-1https://bugzilla.redhat.com/show_bug.cgi?id=916774https://exchange.xforce.ibmcloud.com/vulnerabilities/83642https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0123http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.3/NEWShttp://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/34b6f60ae586http://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/25dd7c7ac39chttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00106.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00032.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00034.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00101.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022790.htmlhttp://osvdb.org/92543http://rhn.redhat.com/errata/RHSA-2013-0753.htmlhttp://secunia.com/advisories/53109http://secunia.com/advisories/53117http://www.mandriva.com/security/advisories?name=MDVSA-2013:146http://www.securityfocus.com/bid/59281http://www.ubuntu.com/usn/USN-1804-1https://bugzilla.redhat.com/show_bug.cgi?id=916774https://exchange.xforce.ibmcloud.com/vulnerabilities/83642https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0123
2013-04-29
Published