SUSE Security Update: Security update for icedtea-web ______________________________________________________________________________ Announcement ID: SUSE-SU-2013:1520-1 Rating: critical References: #840572 Cross-References: CVE-2012-4540 CVE-2013-4349 Affected Products: SUSE Linux Enterprise Desktop 11 SP3 SUSE Linux Enterprise Desktop 11 SP2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. It includes one version update. Description: This icedtea-web update adds a missing fix for an off-by-one heap-based buffer overflow. bnc#840572: CVE-2013-4349: icedtea-web 1.4.1 fixes the missing patch for CVE-2012-4540. Security Issues: * CVE-2012-4540 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4540 ...