CVE-2013-1927
published 2013-04-29CVE-2013-1927: The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF…
PriorityP341medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
4.32%
90.1th percentile
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR."
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | icedtea-web | < icedtea-web 1.3.2-1 (bookworm) | icedtea-web 1.3.2-1 (bookworm) |
| opensuse | opensuse | — | — |
| python-gnupg_project | python-gnupg | >= 0.3.5 < 0.3.6 | 0.3.6 |
| redhat | icedtea-web | <= 1.2.2 | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa7.5HIGH
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
IcedTea-Web regression
vendor_ubuntu·2013-04-23·CVSS 5.8
[MEDIUM] IcedTea-Web regression
Title: IcedTea-Web regression
Summary: Due to a regression, IcedTea-Web might not be able to access some sites.
USN-1804-1 fixed vulnerabilities in IcedTea-Web. This update introduced
a regression with the Java Network Launching Protocol (JNLP) when fetching
content over SSL under certain configurations, such as when using the
community-supported IcedTead 7 browser plugin. This update fixes the
problem.
We apologize for the inconvenience.
Original advisory details:
Jiri Vanek discovered that IcedTea-Web would use the same classloader for
applets from different domains. A remote attacker could exploit this to
expose sensitive information or potentially manipulate applets from other
domains. (CVE-2013-1926)
It was discovered that IcedTea-Web did not properly verify JAR files and
was su
Ubuntu
IcedTea-Web vulnerabilities
vendor_ubuntu·2013-04-18·CVSS 5.8
CVE-2013-1926 [MEDIUM] IcedTea-Web vulnerabilities
Title: IcedTea-Web vulnerabilities
Summary: Two security issues were fixed in IcedTea-Web.
Jiri Vanek discovered that IcedTea-Web would use the same classloader for
applets from different domains. A remote attacker could exploit this to
expose sensitive information or potentially manipulate applets from other
domains. (CVE-2013-1926)
It was discovered that IcedTea-Web did not properly verify JAR files and
was susceptible to the GIFAR attack. If a user were tricked into opening a
malicious website, a remote attacker could potentially exploit this to
execute code under certain circumstances. (CVE-2013-1927)
Instructions: After a standard system update you need to restart your browser to make
all the necessary changes.
Red Hat
icedtea-web: GIFAR issue
vendor_redhat·2013-04-17·CVSS 6.8
CVE-2013-1927 [MEDIUM] icedtea-web: GIFAR issue
icedtea-web: GIFAR issue
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR."
Debian
CVE-2013-1927: icedtea-web - The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attacke...
vendor_debian·2013·CVSS 6.8
CVE-2013-1927 [MEDIUM] CVE-2013-1927: icedtea-web - The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attacke...
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR."
Scope: local
bookworm: resolved (fixed in 1.3.2-1)
bullseye: resolved (fixed in 1.3.2-1)
forky: resolved (fixed in 1.3.2-1)
sid: resolved (fixed in 1.3.2-1)
trixie: resolved (fixed in 1.3.2-1)
GHSA
GHSA-h9w9-hgh2-mwrp: The IcedTea-Web plugin before 1
ghsa_unreviewed·2022-05-14
CVE-2013-1927 [MEDIUM] GHSA-h9w9-hgh2-mwrp: The IcedTea-Web plugin before 1
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR."
GHSA
python-gnupg's shell_quote function does not properly quote strings
ghsa·2018-11-06·CVSS 7.5
CVE-2014-1927 [HIGH] CWE-20 python-gnupg's shell_quote function does not properly quote strings
python-gnupg's shell_quote function does not properly quote strings
The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "$(" command-substitution sequences, a different vulnerability than CVE-2014-1928. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
GHSA
python-gnupg's shell_quote function does not properly escape characters
ghsa·2018-11-06·CVSS 7.5
CVE-2014-1928 [HIGH] CWE-20 python-gnupg's shell_quote function does not properly escape characters
python-gnupg's shell_quote function does not properly escape characters
The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "\" (backslash) characters to form multi-command sequences, a different vulnerability than CVE-2014-1927. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.
OSV
CVE-2013-1927: The IcedTea-Web plugin before 1
osv·2013-04-29·CVSS 6.8
CVE-2013-1927 [MEDIUM] CVE-2013-1927: The IcedTea-Web plugin before 1
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR."
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-7323 CVE-2014-1927 CVE-2014-1928 CVE-2014-1929 python-gnupg: incorrect fix against shell injection
bugzilla·2014-02-05·CVSS 7.5
CVE-2013-7323 [HIGH] CVE-2013-7323 CVE-2014-1927 CVE-2014-1928 CVE-2014-1929 python-gnupg: incorrect fix against shell injection
CVE-2013-7323 CVE-2014-1927 CVE-2014-1928 CVE-2014-1929 python-gnupg: incorrect fix against shell injection
It was found [1] that the fix for improved shell quoting to guard against shell injection, released in version 0.3.5 [2] of python-gnupg, is not sufficient.
This issue has been reported upstream [3].
[1] http://seclists.org/oss-sec/2014/q1/243
[2] https://code.google.com/p/python-gnupg/
[3] https://code.google.com/p/python-gnupg/issues/detail?id=98#c4
Discussion:
Created python-gnupg tracking bugs for this issue:
Affects: fedora-all [bug 1061600]
---
updates pushed to updates-testing for f19,f20,el6 (and built in rawhide)
---
This was assigned multiple CVE numbers:
CVE-2013-7323 Unrestricted use of unquoted strings in a shell,
within version 0.3.4
CVE-2014-1927 Erroneous
Bugzilla
CVE-2013-1927 icedtea-web: GIFAR issue
bugzilla·2012-12-06·CVSS 9.0
CVE-2013-1927 [CRITICAL] CVE-2013-1927 icedtea-web: GIFAR issue
CVE-2013-1927 icedtea-web: GIFAR issue
Current IcedTea-Web versions are affected by GIFAR issue. It is possible to combine GIF image with Java JAR into a single file, that is both valid GIF as well as valid JAR/ZIP file. This issue can be used to execute Java applet in the context of the site that allows untrusted users to upload images in GIF format.
This problem was previously fixed in Oracle and IBM Java plugins as CVE-2008-5343 (bug 474790).
References:
http://en.wikipedia.org/wiki/Gifar
http://xs-sniper.com/blog/2008/12/17/sun-fixes-gifars/
http://riosec.com/how-to-create-a-gifar
Discussion:
Created attachment 659469
proposed patch
This patch is fixing the issue. Troubles will come when not just zip jars will be used (and so jar header will change) - eg pack2000 in jdk8.
Otherwi
http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.3/NEWShttp://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/cb58b31c450ehttp://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/19f5282f53e8http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00106.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00032.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00034.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00101.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022790.htmlhttp://osvdb.org/92544http://rhn.redhat.com/errata/RHSA-2013-0753.htmlhttp://secunia.com/advisories/53109http://secunia.com/advisories/53117http://www.mandriva.com/security/advisories?name=MDVSA-2013:146http://www.securityfocus.com/bid/59286http://www.ubuntu.com/usn/USN-1804-1https://bugzilla.redhat.com/show_bug.cgi?id=884705https://exchange.xforce.ibmcloud.com/vulnerabilities/83640https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0123http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.3/NEWShttp://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/cb58b31c450ehttp://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/19f5282f53e8http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00013.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00106.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2013-05/msg00032.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00030.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00034.htmlhttp://lists.opensuse.org/opensuse-updates/2013-06/msg00101.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-April/022790.htmlhttp://osvdb.org/92544http://rhn.redhat.com/errata/RHSA-2013-0753.htmlhttp://secunia.com/advisories/53109http://secunia.com/advisories/53117http://www.mandriva.com/security/advisories?name=MDVSA-2013:146http://www.securityfocus.com/bid/59286http://www.ubuntu.com/usn/USN-1804-1https://bugzilla.redhat.com/show_bug.cgi?id=884705https://exchange.xforce.ibmcloud.com/vulnerabilities/83640https://wiki.mageia.org/en/Support/Advisories/MGASA-2013-0123
2013-04-29
Published