Required CVE Record Information
Description
The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of "an inappropriate security descriptor."
References 11 Total
- lists.fedoraproject.org: FEDORA-2011-1631 vendor-advisory
- security.gentoo.org: GLSA-201406-32 vendor-advisory
- lists.fedoraproject.org: FEDORA-2011-1645 vendor-advisory
- securityfocus.com: 46439 vdb-entry
- exchange.xforce.ibmcloud.com: icedtea-jnlpclassloader-priv-esc(65534) vdb-entry
- http://dbhole.wordpress.com/2011/02/15/icedtea-web-1-0-1-released/
- secunia.com: 43350 third-party-advisory
- debian.org: DSA-2224 vendor-advisory
- oval.cisecurity.org: oval:org.mitre.oval:def:14117 vdb-entrysignature
- https://bugzilla.redhat.com/show_bug.cgi?id=677332
- mandriva.com: MDVSA-2011:054 vendor-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 11 Total
- lists.fedoraproject.org: FEDORA-2011-1631 vendor-advisoryx_transferred
- security.gentoo.org: GLSA-201406-32 vendor-advisoryx_transferred
- lists.fedoraproject.org: FEDORA-2011-1645 vendor-advisoryx_transferred
- securityfocus.com: 46439 vdb-entryx_transferred
- exchange.xforce.ibmcloud.com: icedtea-jnlpclassloader-priv-esc(65534) vdb-entryx_transferred
- http://dbhole.wordpress.com/2011/02/15/icedtea-web-1-0-1-released/ x_transferred
- secunia.com: 43350 third-party-advisoryx_transferred
- debian.org: DSA-2224 vendor-advisoryx_transferred
- oval.cisecurity.org: oval:org.mitre.oval:def:14117 vdb-entrysignaturex_transferred
- https://bugzilla.redhat.com/show_bug.cgi?id=677332 x_transferred
- mandriva.com: MDVSA-2011:054 vendor-advisoryx_transferred