PT-2012-4700 · Icedtea Web+3 · Icedtea-Web+3

Publicado

2012-07-31

·

Atualizado

2014-10-04

·

CVE-2012-3423

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IcedTea-Web plugin versions prior to 1.2.1
Description The issue allows remote attackers to cause a denial of service, obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet, due to improper handling of NPVariant NPStrings without NUL terminators.
Recommendations For versions prior to 1.2.1, update to version 1.2.1 or later to resolve the issue.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2012_1132
CVE-2012-3423
OPENSUSE-SU-2024:10316-1
RHSA-2012:1132
RHSA-2012_1132

Produtos afetados

Centos
Icedtea-Web
Red Hat
Suse