CVE-2010-2783
published 2019-10-31CVE-2010-2783: IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.
PriorityP350critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.94%
77.8th percentile
IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| icedtea | icedtea6 | — | — |
| redhat | icedtea6 | < 1.7.4 | 1.7.4 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_redhat9.1CRITICAL
vendor_ubuntu9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3g68-hg24-4xxq: IcedTea6 before 1
ghsa_unreviewed·2022-04-21
CVE-2010-2783 [CRITICAL] CWE-200 GHSA-3g68-hg24-4xxq: IcedTea6 before 1
IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.
Ubuntu
OpenJDK vulnerabilities
vendor_ubuntu·2010-08-16·CVSS 9.1
CVE-2010-2548 [CRITICAL] OpenJDK vulnerabilities
Title: OpenJDK vulnerabilities
Summary: Exposed arbitrary file contents to remote systems.
It was discovered that the IcedTea plugin did not correctly check certain
accesses. If a user or automated system were tricked into running a
specially crafted Java applet, a remote attacker could read arbitrary
files with user privileges, leading to a loss of privacy. (CVE-2010-2548,
CVE-2010-2783)
Instructions: After a standard system update you need to restart any Java applications
to make all the necessary changes.
Red Hat
IcedTea: 'Extended JNLP Services' arbitrary file access
vendor_redhat·2010-07-28·CVSS 9.1
CVE-2010-2783 [CRITICAL] IcedTea: 'Extended JNLP Services' arbitrary file access
IcedTea: 'Extended JNLP Services' arbitrary file access
IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.
Statement: This issue does not affect the version of the java-1.6.0-openjdk package, as
shipped with Red Hat Enterprise Linux 5.
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
http://blog.fuseyism.com/index.php/2010/07/28/icedtea6-174-released/http://security.gentoo.org/glsa/glsa-201406-32.xmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2783https://security-tracker.debian.org/tracker/CVE-2010-2783http://blog.fuseyism.com/index.php/2010/07/28/icedtea6-174-released/http://security.gentoo.org/glsa/glsa-201406-32.xmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2783https://security-tracker.debian.org/tracker/CVE-2010-2783
2019-10-31
Published