Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10185

Опубликовано: 31 июл. 2019
Источник: redhat
CVSS3: 8.2

Описание

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.

It was found that icedtea-web was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.

Меры по смягчению последствий

No known mitigation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6icedtea-webOut of support scope
Red Hat Enterprise Linux 7icedtea-webFixedRHSA-2019:200331.07.2019
Red Hat Enterprise Linux 8icedtea-webFixedRHSA-2019:200431.07.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1724989icedtea-web: directory traversal in the nested jar auto-extraction leading to arbitrary file overwrite

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 6 лет назад

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.

CVSS3: 8.6
nvd
больше 6 лет назад

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.

CVSS3: 8.6
debian
больше 6 лет назад

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was ...

CVSS3: 8.6
github
больше 3 лет назад

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.

CVSS3: 8.6
fstec
больше 6 лет назад

Уязвимость плагина IcedTea-Web, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю записать произвольные файлы в файловую систему устройства

8.2 High

CVSS3