SuSE: 2013:1174-1: important: icedtea-web
Summary
This update to IcedTea-Web 1.4 provides the following fixes and enhancements: * Security updates o CVE-2013-1926, RH916774: Class-loader incorrectly shared for applets with same relative-path o CVE-2013-1927, RH884705: fixed gifar vulnerabilit o CVE-2012-3422, RH840592: Potential read from an uninitialized memory location o CVE-2012-3423, RH841345: Incorrect handling of not 0-terminated strings o CVE-2013-1927, RH884705: fixed gifar vulnerability o CVE-2013-1926, RH916774: Class-loader incorrectly shared for applets with same relative-path. * NetX o PR1027: DownloadService is not supported by IcedTea-Web o PR725: JNLP applications will prompt for creating desktop shortcuts every time they are run o PR1292: Javaws does not resolve versioned jar names with periods correctly o PR580: loads improperly. * Plugin o PR1106: Buffer overflow in plugin table- o PR1166: Embedded JNLP File is not supported in...
Read the Full AdvisoryReferences
#815596 #818768 #825880
Cross- CVE-2012-3422 CVE-2012-3423 CVE-2013-1926
CVE-2013-1927
Affected Products:
SUSE Linux Enterprise Desktop 11 SP3
https://www.suse.com/security/cve/CVE-2012-3422.html
https://www.suse.com/security/cve/CVE-2012-3423.html
https://www.suse.com/security/cve/CVE-2013-1926.html
https://www.suse.com/security/cve/CVE-2013-1927.html
https://bugzilla.novell.com/815596
https://bugzilla.novell.com/818768
https://bugzilla.novell.com/825880
https://login.microfocus.com/nidp/app/login