CVE-2013-6493
03.03.2014, 16:55
The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugin.cc in IcedTea-Web before 1.4.2 allows local users to read the messages between a Java applet and a web browser by pre-creating a temporary socket file with a predictable name in /tmp.Enginsight
| Vendor | Product | Version |
|---|---|---|
| redhat | icedtea-web | 𝑥 ≤ 1.3.2 |
| redhat | icedtea-web | 1.0.1 |
| redhat | icedtea-web | 1.0.2 |
| redhat | icedtea-web | 1.0.3 |
| redhat | icedtea-web | 1.0.4 |
| redhat | icedtea-web | 1.0.5 |
| redhat | icedtea-web | 1.0.6 |
| redhat | icedtea-web | 1.1 |
| redhat | icedtea-web | 1.1.1 |
| redhat | icedtea-web | 1.1.2 |
| redhat | icedtea-web | 1.1.3 |
| redhat | icedtea-web | 1.1.4 |
| redhat | icedtea-web | 1.1.5 |
| redhat | icedtea-web | 1.1.6 |
| redhat | icedtea-web | 1.1.7 |
| redhat | icedtea-web | 1.2 |
| redhat | icedtea-web | 1.2.1 |
| redhat | icedtea-web | 1.2.2 |
| redhat | icedtea-web | 1.3 |
| redhat | icedtea-web | 1.3.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References