Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2011-1100

Опубликовано: 27 июл. 2011
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2011-1100: icedtea-web security update (MODERATE)

[1.0.4-2]

  • Added patch to make plugin table size mismatch a warning instead of error

[1.0.4-1]

  • Bump to 1.0.4
  • Resolves rhbz#718180

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

icedtea-web

1.0.4-2.el6_1

icedtea-web-javadoc

1.0.4-2.el6_1

Oracle Linux i686

icedtea-web

1.0.4-2.el6_1

icedtea-web-javadoc

1.0.4-2.el6_1

Связанные CVE

Связанные уязвимости

ubuntu
около 11 лет назад

The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to trick victims into granting access to local files by modifying the content of the Java Web Start Security Warning dialog box to represent a different filename than the file for which access will be granted.

redhat
почти 14 лет назад

The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to trick victims into granting access to local files by modifying the content of the Java Web Start Security Warning dialog box to represent a different filename than the file for which access will be granted.

nvd
около 11 лет назад

The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to trick victims into granting access to local files by modifying the content of the Java Web Start Security Warning dialog box to represent a different filename than the file for which access will be granted.

debian
около 11 лет назад

The Java Network Launching Protocol (JNLP) implementation in IcedTea6 ...

ubuntu
около 11 лет назад

The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to obtain the username and full path of the home and cache directories by accessing properties of the ClassLoader.