PT-2014-3140 · Icedtea+1 · Icedtea-Web+1
Murray Mcallister
·
Published
2014-02-10
·
Updated
2014-03-19
·
CVE-2013-6493
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IcedTea-Web versions prior to 1.4.2
Description
The issue affects the LiveConnect implementation, allowing local users to intercept communication between a Java applet and a web browser. This is achieved by pre-creating a temporary socket file with a predictable name in /tmp, enabling the user to read the messages exchanged between the applet and the browser.
Recommendations
For versions prior to 1.4.2, update to version 1.4.2 or later to resolve the issue.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Icedtea-Web
Suse