Ubuntu

“icedtea-web” 1.2.3-0ubuntu0.11.10.1 source package in Ubuntu

Changelog

icedtea-web (1.2.3-0ubuntu0.11.10.1) oneiric-security; urgency=low

  [ Matthias Klose ]
  * IcedTea-Web 1.2.3 release.
  * Security Updates:
    - CVE-2013-1927: fixed gifar vulnerability.
    - CVE-2013-1926: Class-loader incorrectly shared for applets with same
      relative-path.
  * Common:
    - PR1161: X509VariableTrustManager does not work correctly with OpenJDK7.
  * NetX:
    - PR580: http://www.horaoficial.cl/ loads improperly.
  * Plugin:
    - PR1157: Applets can hang browser after fatal exception.

  [ Jamie Strandboge ]
  * debian/rules: generate icedtea-plugin meta package
  * debian/icedtea-netx.postinst.in: skip update-alternatives on
    openjdk-7 binaries if they don't exist
  * Regenerate the control file

icedtea-web (1.2.2-0ubuntu1) precise-proposed; urgency=low

  * Update to the 1.2.2 bug fix release. LP: #1131479.
    - Includes security fixes uploaded earlier.
    - Bug fixes:
      - PR1106: Buffer overflow in plugin table.
      - PR898: signed applications with big jnlp-file doesn't start (webstart
        affect like "frozen").
      - PR811: javaws is not handling urls with spaces (and other characters
        needing encoding) correctly.
      - S816592: icedtea-web not loading GeoGebra java applets in Firefox
        or Chrome.
      - PR863: Error passing strings to applet methods in Chromium.
      - PR895: IcedTea-Web searches for missing classes on each loadClass
        or findClass.
      - PR518: NPString.utf8characters not guaranteed to be nul-terminated.
      - Disambiguate signed applet security prompt from certificate warning.
  * Search both OpenJDK-6 and OpenJDK-7 when starting itweb-settings.
    LP: #1078424.

icedtea-web (1.2-2ubuntu1.3) precise-security; urgency=low

  * SECURITY UPDATE: Fix denial of service in exception handling
    - debian/patches/icedtea-web-CVE-2012-4540.patch: adjust off by one in
      exception string storage in IcedTeaScriptablePluginObject.cc. Also fix
      two memory leaks.
    - CVE-2012-4540

icedtea-web (1.2-2ubuntu1.2) precise-proposed; urgency=low

  * debian/patches/fix-plugin-error-on-chromium.patch: fix plugin
    table initialization to check only that the subset of hooks that
    it uses exists. (LP: #1025553)
  * debian/control, debian/control.common: adjust so that
    icedtea-netx-common replaces icedtea-plugin in oneiric
    (LP: #1002516)

icedtea-web (1.2-2ubuntu1.1) precise-security; urgency=low

  * SECURITY UPDATE: uninitialized pointer use flaw
    - debian/patches/icedtea-web-CVE-2012-3422.patch: check for empty
      instance_to_id_map hash and return error if so.
    - CVE-2012-3422
  * SECURITY UPDATE: incorrect handling of non NULL terminated strings
    - debian/patches/icedtea-web-CVE-2012-3423.patch: ensure NPVariant
      NPStrings are NULL terminated.
    - CVE-2012-3423
  * debian/control, debian/control.common: add replaces on icedtea-net
    and icedtea-6-plugin for conflicting files in older releases,
    caused by icedtea-web security pocket backport to those releases
    in conjunction with openjdk-6 security backport (LP: #1024708)

icedtea-web (1.2-2ubuntu1) precise; urgency=low

  * Regenerate the control file.
 -- Jamie Strandboge <email address hidden>   Wed, 17 Apr 2013 17:52:21 -0500

Upload details

Uploaded by:
Jamie Strandboge on 2013-04-17
Uploaded to:
Oneiric
Original maintainer:
Ubuntu Developers
Component:
main
Architectures:
any
Section:
java
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size MD5 Checksum
icedtea-web_1.2.3.orig.tar.gz 880.4 KiB ab56d94251975a9bb5359ea85136ea79
icedtea-web_1.2.3-0ubuntu0.11.10.1.debian.tar.gz 16.5 KiB 8aba9328641692b4e18a6c0279195e41
icedtea-web_1.2.3-0ubuntu0.11.10.1.dsc 2.2 KiB 2a5e94b6aea3b9219aa3900d4ac328ac

Binary packages built by this source

icedtea-6-plugin: web browser plugin based on OpenJDK and IcedTea to execute Java applets

 IcedTeaPlugin is a web browser plugin to execute Java applets, supporting
 LiveConnect/JavaScript. It is targeted for xulrunner-1.9 and compatible
 browsers that support the NPAPI.

icedtea-netx: NetX - implementation of the Java Network Launching Protocol (JNLP)

 NetX provides a drop-in replacement for javaws (Java Web Start). Since
 upstream NetX is dormant, IcedTea is hosting and modifying the sources
 in the IcedTea-Web directory.
 .
 IcedTea's NetX currently supports verification of signed jars, trusted
 certificate storing, system certificate store checking, and provides
 the services specified by the jnlp API.

icedtea-plugin: web browser plugin to execute Java applets (dependency package)

 IcedTeaPlugin is a web browser plugin to execute Java applets, supporting
 LiveConnect/JavaScript. It is targeted for xulrunner-1.9 and compatible
 browsers that support the NPAPI.
 .
 This is a dependency package, it can be safely removed after upgrade.

icedtea6-plugin: web browser plugin to execute Java applets (dependency package)

 IcedTeaPlugin is a web browser plugin to execute Java applets, supporting
 LiveConnect/JavaScript. It is targeted for xulrunner-1.9 and compatible
 browsers that support the NPAPI.
 .
 This is a dependency package, it can be safely removed after upgrade.