FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-3422

This CVE name corresponds to:

Entered Topic
2012-08-13 Several vulnerabilities found in IcedTea-Web

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-3422
Phase Assigned(20120614)

Description

The getFirstInTableInstance function in the IcedTea-Web plugin before 1.2.1 returns an uninitialized pointer when the instance_to_id_map hash is empty, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted web page, which causes an uninitialized memory location to be read.

References

Source Reference
MISC https://bugzilla.redhat.com/show_bug.cgi?id=840592
CONFIRM http://icedtea.classpath.org/hg/release/icedtea-web-1.2/file/icedtea-web-1.2.1/NEWS
GENTOO GLSA-201406-32
REDHAT RHSA-2012:1132
SUSE SUSE-SU-2012:0979
SUSE openSUSE-SU-2012:0981
SUSE openSUSE-SU-2012:0982
SUSE openSUSE-SU-2013:0826
SUSE SUSE-SU-2013:0851
SUSE openSUSE-SU-2013:0893
SUSE openSUSE-SU-2013:0966
SUSE SUSE-SU-2013:1174
UBUNTU USN-1521-1
SECUNIA 50089