This bug was fixed in the package icedtea-web - 1.2.3-0ubuntu0.11.10.1 --------------- icedtea-web (1.2.3-0ubuntu0.11.10.1) oneiric-security; urgency=low
[ Matthias Klose ] * IcedTea-Web 1.2.3 release. * Security Updates: - CVE-2013-1927: fixed gifar vulnerability. - CVE-2013-1926: Class-loader incorrectly shared for applets with same relative-path. * Common: - PR1161: X509VariableTrustManager does not work correctly with OpenJDK7. * NetX: - PR580: http://www.horaoficial.cl/ loads improperly. * Plugin: - PR1157: Applets can hang browser after fatal exception. [ Jamie Strandboge ] * debian/rules: generate icedtea-plugin meta package * debian/icedtea-netx.postinst.in: skip update-alternatives on openjdk-7 binaries if they don't exist * Regenerate the control file icedtea-web (1.2.2-0ubuntu1) precise-proposed; urgency=low * Update to the 1.2.2 bug fix release. LP: #1131479. - Includes security fixes uploaded earlier. - Bug fixes: - PR1106: Buffer overflow in plugin table. - PR898: signed applications with big jnlp-file doesn't start (webstart affect like "frozen"). - PR811: javaws is not handling urls with spaces (and other characters needing encoding) correctly. - S816592: icedtea-web not loading GeoGebra java applets in Firefox or Chrome. - PR863: Error passing strings to applet methods in Chromium. - PR895: IcedTea-Web searches for missing classes on each loadClass or findClass. - PR518: NPString.utf8characters not guaranteed to be nul-terminated. - Disambiguate signed applet security prompt from certificate warning. * Search both OpenJDK-6 and OpenJDK-7 when starting itweb-settings. LP: #1078424. icedtea-web (1.2-2ubuntu1.3) precise-security; urgency=low * SECURITY UPDATE: Fix denial of service in exception handling - debian/patches/icedtea-web-CVE-2012-4540.patch: adjust off by one in exception string storage in IcedTeaScriptablePluginObject.cc. Also fix two memory leaks. - CVE-2012-4540 icedtea-web (1.2-2ubuntu1.2) precise-proposed; urgency=low * debian/patches/fix-plugin-error-on-chromium.patch: fix plugin table initialization to check only that the subset of hooks that it uses exists. (LP: #1025553) * debian/control, debian/control.common: adjust so that icedtea-netx-common replaces icedtea-plugin in oneiric (LP: #1002516) icedtea-web (1.2-2ubuntu1.1) precise-security; urgency=low * SECURITY UPDATE: uninitialized pointer use flaw - debian/patches/icedtea-web-CVE-2012-3422.patch: check for empty instance_to_id_map hash and return error if so. - CVE-2012-3422 * SECURITY UPDATE: incorrect handling of non NULL terminated strings - debian/patches/icedtea-web-CVE-2012-3423.patch: ensure NPVariant NPStrings are NULL terminated. - CVE-2012-3423 * debian/control, debian/control.common: add replaces on icedtea-net and icedtea-6-plugin for conflicting files in older releases, caused by icedtea-web security pocket backport to those releases in conjunction with openjdk-6 security backport (LP: #1024708) icedtea-web (1.2-2ubuntu1) precise; urgency=low * Regenerate the control file. -- Jamie Strandboge <ja...@ubuntu.com> Wed, 17 Apr 2013 17:52:21 -0500 ** Changed in: icedtea-web (Ubuntu) Status: Invalid => Fix Released ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2012-3422 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2012-3423 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2012-4540 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2013-1926 ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi?name=2013-1927 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1002516 Title: package icedtea-netx-common 1.2-2ubuntu1 failed to install/upgrade: trying to overwrite '/usr/share/icedtea-web/plugin.jar', which is also in package icedtea-plugin 1.1.3-1ubuntu1.1 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/icedtea-web/+bug/1002516/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs