CVE-2013-6493

Publication date 3 March 2014

Last updated 24 July 2024


Ubuntu priority

The LiveConnect implementation in plugin/icedteanp/IcedTeaNPPlugin.cc in IcedTea-Web before 1.4.2 allows local users to read the messages between a Java applet and a web browser by pre-creating a temporary socket file with a predictable name in /tmp.

Status

Package Ubuntu Release Status
icedtea-web 13.10 saucy
Fixed 1.4-3ubuntu2.1
12.10 quantal
Fixed 1.3.2-1ubuntu0.12.10.3
12.04 LTS precise
Fixed 1.2.3-0ubuntu0.12.04.4
10.04 LTS lucid Ignored end of life

References

Related Ubuntu Security Notices (USN)

    • USN-2131-1
    • IcedTea Web vulnerability
    • 6 March 2014

Other references