Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-2004

Опубликовано: 05 авг. 2019
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2019-2004: icedtea-web security update (IMPORTANT)

[1.7.1-16]

  • Added Patch5, testTuning.patch to make tests pass inclean envirnment
  • Resolves: rhbz#1724958

[1.7.1-16]

  • added patch1, patch4 and patch11 to fix CVE-2019-10182
  • added patch2 to fix CVE-2019-10181
  • added patch3 and patch33 to fix CVE-2019-10185
  • Resolves: rhbz#1724958
  • Resolves: rhbz#1725928
  • Resolves: rhbz#1724989

[-1.7.1-10]

  • added gating

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

icedtea-web

1.7.1-17.el8_0

icedtea-web-javadoc

1.7.1-17.el8_0

Oracle Linux x86_64

icedtea-web

1.7.1-17.el8_0

icedtea-web-javadoc

1.7.1-17.el8_0

Связанные уязвимости

suse-cvrf
больше 6 лет назад

Security update for icedtea-web

suse-cvrf
почти 4 года назад

Security update for icedtea-web

suse-cvrf
больше 6 лет назад

Security update for icedtea-web

oracle-oval
больше 6 лет назад

ELSA-2019-2003: icedtea-web security update (IMPORTANT)

CVSS3: 8.6
ubuntu
больше 6 лет назад

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.