An uninitialized pointer use flaw was found in IcedTea-Web web browser plugin. A malicious web page could use this flaw make IcedTea-Web browser plugin pass invalid pointer to a web browser. Depending on the browser used, it may cause the browser to crash or possibly execute arbitrary code. The get_cookie_info() and get_proxy_info() call getFirstInTableInstance() with the instance_to_id_map hash as a parameter. If instance_to_id_map is empty (which can happen when plugin was recently removed), getFirstInTableInstance() returns an uninitialized pointer. http://icedtea.classpath.org/hg/icedtea-web/file/01544fb82384/plugin/icedteanp/IcedTeaNPPlugin.cc#l292
Created attachment 598511 [details] Fix for 1.1/1.2/1.3/HEAD
Acknowledgment: Red Hat would like to thank Chamal De Silva for reporting this issue.
Lifting embargo.
Created icedtea-web tracking bugs for this issue Affects: fedora-all [bug 844770]
Upstream commits: http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/ec09874d2716 http://icedtea.classpath.org/hg/release/icedtea-web-1.1/rev/109bec81dd4b
Fixed upstream in IcedTea-web 1.1.6 and 1.2.1: http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2012-July/019580.html
This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2012:1132 https://rhn.redhat.com/errata/RHSA-2012-1132.html
icedtea-web-1.3-1.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.
icedtea-web-1.3-1.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report.