MGASA-2014-0049

Source
https://advisories.mageia.org/MGASA-2014-0049.html
Import Source
https://advisories.mageia.org/MGASA-2014-0049.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0049
Upstream
Published
2014-02-10T20:20:14Z
Modified
2026-04-16T06:22:26.392666221Z
Summary
Updated icedtea-web packages fix CVE-2013-6493
Details

Updated icedtea-web packages fix security vulnerability:

LiveConnect provides a gateway between the JavaScript engine in the web browser and Java applets. An insecure temporary file use flaw was found in the LiveConnect implementation in the IcedTea-Web browser plug-in. A malicious, local user could possibly use this flaw to inject or read the communication between a Java applet and web browser of a different user's session (CVE-2013-6493).

References
Credits

Affected packages

Mageia:3 / icedtea-web

Package

Name
icedtea-web
Purl
pkg:rpm/mageia/icedtea-web?arch=source&distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.2-1.mga3

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0049.json"

Mageia:4 / icedtea-web

Package

Name
icedtea-web
Purl
pkg:rpm/mageia/icedtea-web?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.2-1.mga4

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2014-0049.json"