SUSE Security Update: Security update for icedtea-web
______________________________________________________________________________

Announcement ID:    SUSE-SU-2012:0979-1
Rating:             important
References:         #773458 
Cross-References:   CVE-2012-3422 CVE-2012-3423
Affected Products:
                    SUSE Linux Enterprise Desktop 11 SP2
                    SUSE Linux Enterprise Desktop 11 SP1
______________________________________________________________________________

   An update that fixes two vulnerabilities is now available.
   It includes one version update.

Description:


   The icedtea-web Java browser plugin was updated to 1.2.1 to
   fix security  issues and bugs.

   * CVE-2012-3422: Potential read from a uninitialized
   memory location has been fixed.
   * CVE-2012-3423: Incorrect handling of not-0 terminated
   strings has been fixed.

   Security Issue references:

   * CVE-2012-3422
   
   * CVE-2012-3423
   


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Desktop 11 SP2:

      zypper in -t patch sledsp2-icedtea-web-6626

   - SUSE Linux Enterprise Desktop 11 SP1:

      zypper in -t patch sledsp1-icedtea-web-6621

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64) [New Version: 1.2.1]:

      icedtea-web-1.2.1-0.7.1

   - SUSE Linux Enterprise Desktop 11 SP1 (i586 x86_64) [New Version: 1.2.1]:

      icedtea-web-1.2.1-0.2.1


References:

   https://www.suse.com/security/cve/CVE-2012-3422.html
   https://www.suse.com/security/cve/CVE-2012-3423.html
   https://bugzilla.novell.com/773458
   https://login.microfocus.com/nidp/app/login
   https://login.microfocus.com/nidp/app/login

SuSE: 2012:0979-1: important: icedtea-web

August 9, 2012
An update that fixes two vulnerabilities is now available

Summary

The icedtea-web Java browser plugin was updated to 1.2.1 to fix security issues and bugs. * CVE-2012-3422: Potential read from a uninitialized memory location has been fixed. * CVE-2012-3423: Incorrect handling of not-0 terminated strings has been fixed. Security Issue references: * CVE-2012-3422 * CVE-2012-3423 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Desktop 11 SP2: zypper in -t patch sledsp2-icedtea-web-6626 - SUSE Linux Enterprise Desktop 11 SP1: zypper in -t patch sledsp1-icedtea-web-6621 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Desktop 11 SP2 (i586 x86_64) [New Version: 1.2.1]: icedtea-web-1.2.1-0.7.1 - SUSE Linux Enterprise Desktop 11 SP1 (i586 x86_64) [New Version: 1.2.1]: icedtea-web-1.2.1-0.2.1

References

#773458

Cross- CVE-2012-3422 CVE-2012-3423

Affected Products:

SUSE Linux Enterprise Desktop 11 SP2

SUSE Linux Enterprise Desktop 11 SP1

https://www.suse.com/security/cve/CVE-2012-3422.html

https://www.suse.com/security/cve/CVE-2012-3423.html

https://bugzilla.novell.com/773458

https://login.microfocus.com/nidp/app/login

https://login.microfocus.com/nidp/app/login

Severity
Announcement ID: SUSE-SU-2012:0979-1
Rating: important

Related News