Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-4351

Опубликовано: 20 янв. 2011
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.8

Описание

The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPermission method instead of throwing an exception in certain circumstances, which might allow context-dependent attackers to bypass the intended security policy by creating instances of ClassLoader.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

1.1~20110406-0ubuntu1
hardy

DNE

karmic

DNE

lucid

not-affected

1.2-2ubuntu0.10.04.1
maverick

DNE

natty

not-affected

1.1~20110406-0ubuntu1
oneiric

not-affected

1.1~20110406-0ubuntu1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

released

6b21~pre1-0ubuntu1
hardy

released

6b27-1.12.3-0ubuntu1~08.04.1
karmic

released

6b20-1.9.4-0ubuntu1~9.10.1
lucid

released

6b20-1.9.4-0ubuntu1~10.04.1
maverick

released

6b20-1.9.4-0ubuntu1
natty

released

6b21~pre1-0ubuntu1
oneiric

released

6b21~pre1-0ubuntu1
upstream

released

1.7.7,1.8.4,1.9.4

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

6b18-1.8.8~pre1-0ubuntu1
hardy

DNE

karmic

released

6b18-1.8.4-0ubuntu1~9.10.1
lucid

released

6b18-1.8.4-0ubuntu1~10.04.1
maverick

released

6b18-1.8.5-0ubuntu1
natty

not-affected

6b18-1.8.8~pre1-0ubuntu1
oneiric

not-affected

6b18-1.8.8~pre1-0ubuntu1
upstream

released

1.7.7,1.8.4,1.9.4

Показывать по

РелизСтатусПримечание
dapper

not-affected

devel

DNE

hardy

not-affected

karmic

DNE

lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

upstream

not-affected

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

not-affected

karmic

not-affected

lucid

not-affected

maverick

not-affected

natty

not-affected

oneiric

not-affected

upstream

not-affected

Показывать по

EPSS

Процентиль: 81%
0.01585
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

redhat
больше 14 лет назад

The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPermission method instead of throwing an exception in certain circumstances, which might allow context-dependent attackers to bypass the intended security policy by creating instances of ClassLoader.

nvd
больше 14 лет назад

The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPermission method instead of throwing an exception in certain circumstances, which might allow context-dependent attackers to bypass the intended security policy by creating instances of ClassLoader.

debian
больше 14 лет назад

The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 ...

github
около 3 лет назад

The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPermission method instead of throwing an exception in certain circumstances, which might allow context-dependent attackers to bypass the intended security policy by creating instances of ClassLoader.

oracle-oval
больше 14 лет назад

ELSA-2011-0176: java-1.6.0-openjdk security update (MODERATE)

EPSS

Процентиль: 81%
0.01585
Низкий

6.8 Medium

CVSS2

Уязвимость CVE-2010-4351