Lucene search

K
ubuntuUbuntuUSN-2131-1
HistoryMar 06, 2014 - 12:00 a.m.

IcedTea Web vulnerability

2014-03-0600:00:00
ubuntu.com
27

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%

Releases

  • Ubuntu 13.10
  • Ubuntu 12.10
  • Ubuntu 12.04

Packages

  • icedtea-web - A web browser plugin to execute Java applets

Details

Michael Scherer discovered that IcedTea Web created temporary directories
in an unsafe fashion. A local attacker could possibly use this issue to
obtain or modify sensitive information from other local user sessions.

OSVersionArchitecturePackageVersionFilename
Ubuntu13.10noarchicedtea-7-plugin< 1.4-3ubuntu2.1UNKNOWN
Ubuntu13.10noarchicedtea-6-plugin< 1.4-3ubuntu2.1UNKNOWN
Ubuntu13.10noarchicedtea-netx< 1.4-3ubuntu2.1UNKNOWN
Ubuntu12.10noarchicedtea-7-plugin< 1.3.2-1ubuntu0.12.10.3UNKNOWN
Ubuntu12.10noarchicedtea-6-plugin< 1.3.2-1ubuntu0.12.10.3UNKNOWN
Ubuntu12.10noarchicedtea-netx< 1.3.2-1ubuntu0.12.10.3UNKNOWN
Ubuntu12.04noarchicedtea-7-plugin< 1.2.3-0ubuntu0.12.04.4UNKNOWN
Ubuntu12.04noarchicedtea-6-plugin< 1.2.3-0ubuntu0.12.04.4UNKNOWN
Ubuntu12.04noarchicedtea-netx< 1.2.3-0ubuntu0.12.04.4UNKNOWN

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%