[ubuntu/saucy-proposed] icedtea-web 1.4-3ubuntu2 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Tue Sep 24 19:42:16 UTC 2013


icedtea-web (1.4-3ubuntu2) saucy; urgency=low

  * SECURITY UPDATE: possible arbitrary code execution via triggering event
    attached to applet
    - debian/patches/CVE-2013-4349.patch: don't allocate error messages on
      heap in plugin/icedteanp/IcedTeaScriptablePluginObject.cc.
    - CVE-2013-4349

Date: Tue, 24 Sep 2013 15:05:29 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/saucy/+source/icedtea-web/1.4-3ubuntu2
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 24 Sep 2013 15:05:29 -0400
Source: icedtea-web
Binary: icedtea-netx icedtea-plugin icedtea-netx-common icedtea-6-plugin icedtea-7-plugin
Architecture: source
Version: 1.4-3ubuntu2
Distribution: saucy
Urgency: low
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Description: 
 icedtea-6-plugin - web browser plugin based on OpenJDK and IcedTea to execute Java a
 icedtea-7-plugin - web browser plugin based on OpenJDK and IcedTea to execute Java a
 icedtea-netx - NetX - implementation of the Java Network Launching Protocol (JNL
 icedtea-netx-common - NetX - implementation of the Java Network Launching Protocol (JNL
 icedtea-plugin - web browser plugin to execute Java applets (dependency package)
Changes: 
 icedtea-web (1.4-3ubuntu2) saucy; urgency=low
 .
   * SECURITY UPDATE: possible arbitrary code execution via triggering event
     attached to applet
     - debian/patches/CVE-2013-4349.patch: don't allocate error messages on
       heap in plugin/icedteanp/IcedTeaScriptablePluginObject.cc.
     - CVE-2013-4349
Checksums-Sha1: 
 5e4b23f173a42c7ad827b3e4f65d652f50e08643 2460 icedtea-web_1.4-3ubuntu2.dsc
 fef836fcabb362264277d69374ec9090dbbaf9e2 33407 icedtea-web_1.4-3ubuntu2.debian.tar.gz
Checksums-Sha256: 
 c8f852739ed0eeb2a6381396917f7b3ad0d709a7dfec34dfe63715549b093dd5 2460 icedtea-web_1.4-3ubuntu2.dsc
 0d865cf1da42f1a86a9c807814374d99577729457c9fda5258e48cff40a74373 33407 icedtea-web_1.4-3ubuntu2.debian.tar.gz
Files: 
 4f6d0903cf6c77fe5ab942f094fda431 2460 java extra icedtea-web_1.4-3ubuntu2.dsc
 05447fee8e90e84e62e2aa8502ae9302 33407 java extra icedtea-web_1.4-3ubuntu2.debian.tar.gz
Original-Maintainer: OpenJDK Team <openjdk at lists.launchpad.net>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)

iQIcBAEBCgAGBQJSQeqBAAoJEGVp2FWnRL6TZS8P/1+eojAytSFyf2jcQv1jzfEn
BiYAPMba3wGOg2cCUpm0fhu4zUz5NP60ARkCFWnBIZ+PmRjbAd03F/EwqTHnF8q+
tADjCT5Or7R7fCUOywx4+5ZdGKRtK4WmE+h0AEnbhyYF55MBR694f1fnAOdslsJH
uwgNcAFlF5/mTqHQjaIDdvR14vfjV3yk8/8oOEfTfI5e2et8BBt4vOgU9qHDutZT
SQY9BE8udNhtHY/RtfiiY1wxshu3Zco4KJf+iyALTqSCDpn/RA8CnPsZKy9f3OCL
vA1AuT+U4vofvBvtLpnY8JXbK+JGvm3RH/gvEUoDAvbQl4IOAcQ+KwNmNYJxFoOi
k54aerMXVPUai8TXwhkNp56PMMuB6AscJJV9kVpWK+C7QLhsRh5h/wEFfhzumR/Y
T/0pmnvnfvWqE0M189q5GXVBeO9ejIdLHvr8I4UhkpS0LmZaixN+F4zf2IyA0bnJ
Z9yCnQ230ea0dU/h13m+7atKpdMZ8sZkglg6g+gE+SbBivZpLi9ftnCNMVc2ojVV
df6AHQS/61eBiCrBINQFbvKFGWDrf8U+eM3W/33wL86RpXX98yedAr9zGpWm8m1c
Sbl7isr6L3okoiybRG08+TUKZ59JT6iluf6li6NW6OoK9xoUXsWOQiW9w0IFmOXM
r/A3AKZYVrheC07eCIR1
=O3KF
-----END PGP SIGNATURE-----


More information about the Saucy-changes mailing list