CVE-2010-2548
published 2019-10-31CVE-2010-2548: IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
PriorityP349critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.99%
78.5th percentile
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| icedtea | icedtea6 | — | — |
| redhat | icedtea6 | < 1.7.4 | 1.7.4 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_redhat9.1CRITICAL
vendor_ubuntu9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2010-08-16·CVSS 9.1
CVE-2010-2548 [CRITICAL] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Exposed arbitrary file contents to remote systems.
It was discovered that the IcedTea plugin did not correctly check certain
accesses. If a user or automated system were tricked into running a
specially crafted Java applet, a remote attacker could read arbitrary
files with user privileges, leading to a loss of privacy. (CVE-2010-2548,
CVE-2010-2783)
Instructions: After a standard system update you need to restart any Java applications
to make all the necessary changes.
Red Hat
IcedTea Incomplete property access check for unsigned applications
vendor_redhat·2010-07-28·CVSS 9.1
CVE-2010-2548 [CRITICAL] IcedTea Incomplete property access check for unsigned applications
IcedTea Incomplete property access check for unsigned applications
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
Statement: This issue does not affect the version of the java-1.6.0-openjdk package, as
shipped with Red Hat Enterprise Linux 5.
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 6) - Affected
GHSA
GHSA-w978-mmpv-hphg: IcedTea6 before 1
ghsa_unreviewed·2022-04-21
CVE-2010-2548 [CRITICAL] CWE-863 GHSA-w978-mmpv-hphg: IcedTea6 before 1
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
No detection rules found.
No public exploits indexed.
http://blog.fuseyism.com/index.php/2010/07/28/icedtea6-174-released/https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2548https://security-tracker.debian.org/tracker/CVE-2010-2548http://blog.fuseyism.com/index.php/2010/07/28/icedtea6-174-released/https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2548https://security-tracker.debian.org/tracker/CVE-2010-2548
2019-10-31
Published