This bug was fixed in the package icedtea-web - 1.2.3-0ubuntu0.11.10.1 --------------- icedtea-web (1.2.3-0ubuntu0.11.10.1) oneiric-security; urgency=low [ Matthias Klose ] * IcedTea-Web 1.2.3 release. * Security Updates: - CVE-2013-1927: fixed gifar vulnerability. - CVE-2013-1926: Class-loader incorrectly shared for applets with same relative-path. * Common: - PR1161: X509VariableTrustManager does not work correctly with OpenJDK7. * NetX: - PR580: http://www.horaoficial.cl/ loads improperly. * Plugin: - PR1157: Applets can hang browser after fatal exception. [ Jamie Strandboge ] * debian/rules: generate icedtea-plugin meta package * debian/icedtea-netx.postinst.in: skip update-alternatives on openjdk-7 binaries if they don't exist * Regenerate the control file icedtea-web (1.2.2-0ubuntu1) precise-proposed; urgency=low * Update to the 1.2.2 bug fix release. LP: #1131479. - Includes security fixes uploaded earlier. - Bug fixes: - PR1106: Buffer overflow in plugin table. - PR898: signed applications with big jnlp-file doesn't start (webstart affect like "frozen"). - PR811: javaws is not handling urls with spaces (and other characters needing encoding) correctly. - S816592: icedtea-web not loading GeoGebra java applets in Firefox or Chrome. - PR863: Error passing strings to applet methods in Chromium. - PR895: IcedTea-Web searches for missing classes on each loadClass or findClass. - PR518: NPString.utf8characters not guaranteed to be nul-terminated. - Disambiguate signed applet security prompt from certificate warning. * Search both OpenJDK-6 and OpenJDK-7 when starting itweb-settings. LP: #1078424. icedtea-web (1.2-2ubuntu1.3) precise-security; urgency=low * SECURITY UPDATE: Fix denial of service in exception handling - debian/patches/icedtea-web-CVE-2012-4540.patch: adjust off by one in exception string storage in IcedTeaScriptablePluginObject.cc. Also fix two memory leaks. - CVE-2012-4540 icedtea-web (1.2-2ubuntu1.2) precise-proposed; urgency=low * debian/patches/fix-plugin-error-on-chromium.patch: fix plugin table initialization to check only that the subset of hooks that it uses exists. (LP: #1025553) * debian/control, debian/control.common: adjust so that icedtea-netx-common replaces icedtea-plugin in oneiric (LP: #1002516) icedtea-web (1.2-2ubuntu1.1) precise-security; urgency=low * SECURITY UPDATE: uninitialized pointer use flaw - debian/patches/icedtea-web-CVE-2012-3422.patch: check for empty instance_to_id_map hash and return error if so. - CVE-2012-3422 * SECURITY UPDATE: incorrect handling of non NULL terminated strings - debian/patches/icedtea-web-CVE-2012-3423.patch: ensure NPVariant NPStrings are NULL terminated. - CVE-2012-3423 * debian/control, debian/control.common: add replaces on icedtea-net and icedtea-6-plugin for conflicting files in older releases, caused by icedtea-web security pocket backport to those releases in conjunction with openjdk-6 security backport (LP: #1024708) icedtea-web (1.2-2ubuntu1) precise; urgency=low * Regenerate the control file. -- Jamie Strandboge