CVE-2012-3423
EPSS 2.8%
Description
The IcedTea-Web plugin before 1.2.1 does not properly handle NPVariant NPStrings without NUL terminators, which allows remote attackers to cause a denial of service (crash), obtain sensitive information from memory, or execute arbitrary code via a crafted Java applet.
How to fix CVE-2012-3423
To remediate CVE-2012-3423, upgrade the affected package to a fixed version below.
- Debian/icedtea-web—upgrade to 1.3-1 or later
Is CVE-2012-3423 being exploited?
Low — EPSS is 2.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.3-1