CVE-2011-0706
published 2011-02-19CVE-2011-0706: The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown…
PriorityP340high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.09%
86.2th percentile
The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of "an inappropriate security descriptor."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| sun | jdk | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
vendor_ubuntu2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2011-03-17·CVSS 2.6
CVE-2010-4448 [LOW] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: OpenJDK 6 vulnerabilities in Ubuntu 10.10 for armel (ARM) architecture.
USN-1079-2 fixed vulnerabilities in OpenJDK 6 for armel (ARM)
architectures in Ubuntu 9.10 and Ubuntu 10.04 LTS. This update fixes
vulnerabilities in OpenJDK 6 for armel (ARM) architectures for Ubuntu
10.10.
Original advisory details:
It was discovered that untrusted Java applets could create domain
name resolution cache entries, allowing an attacker to manipulate
name resolution within the JVM. (CVE-2010-4448)
It was discovered that the Java launcher did not did not properly
setup the LD_LIBRARY_PATH environment variable. A local attacker
could exploit this to execute arbitrary code as the user invoking
the program. (CVE-2010-4450)
It was discovered that within the Swing
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2011-03-15·CVSS 2.6
CVE-2010-4448 [LOW] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
Summary: OpenJDK 6 Vulnerabilities (armel packages only)
USN-1079-1 fixed vulnerabilities in OpenJDK 6 for non-armel (ARM)
architectures. This update provides the corresponding updates for
OpenJDK 6 for use with the armel (ARM) architectures.
In order to build the armel (ARM) OpenJDK 6 update for Ubuntu 10.04
LTS, it was necessary to rebuild binutils and gcj-4.4 from Ubuntu
10.04 LTS updates.
Original advisory details:
It was discovered that untrusted Java applets could create domain
name resolution cache entries, allowing an attacker to manipulate
name resolution within the JVM. (CVE-2010-4448)
It was discovered that the Java launcher did not did not properly
setup the LD_LIBRARY_PATH environment variable. A local attacker
could exploit this to execu
Ubuntu
OpenJDK 6 vulnerabilities
vendor_ubuntu·2011-03-01·CVSS 2.6
CVE-2010-4448 [LOW] OpenJDK 6 vulnerabilities
Title: OpenJDK 6 vulnerabilities
It was discovered that untrusted Java applets could create domain
name resolution cache entries, allowing an attacker to manipulate
name resolution within the JVM. (CVE-2010-4448)
It was discovered that the Java launcher did not did not properly
setup the LD_LIBRARY_PATH environment variable. A local attacker
could exploit this to execute arbitrary code as the user invoking
the program. (CVE-2010-4450)
It was discovered that within the Swing library, forged timer events
could allow bypass of SecurityManager checks. This could allow an
attacker to access restricted resources. (CVE-2010-4465)
It was discovered that certain bytecode combinations confused memory
management within the HotSpot JVM. This could allow an attacker to
cause a denial of service thr
Red Hat
IcedTea multiple signers privilege escalation
vendor_redhat·2011-02-15·CVSS 7.5
CVE-2011-0706 [HIGH] CWE-266 IcedTea multiple signers privilege escalation
IcedTea multiple signers privilege escalation
The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of "an inappropriate security descriptor."
Statement: This issue did not affect the versions of the java-1.6.0-openjdk package as shipped with Red Hat Enterprise Linux 5 and 6.
GHSA
GHSA-6228-hc88-4m3g: The JNLPClassLoader class in IcedTea-Web before 1
ghsa_unreviewed·2022-05-17
CVE-2011-0706 [HIGH] GHSA-6228-hc88-4m3g: The JNLPClassLoader class in IcedTea-Web before 1
The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of "an inappropriate security descriptor."
No detection rules found.
No public exploits indexed.
http://dbhole.wordpress.com/2011/02/15/icedtea-web-1-0-1-released/http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054115.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-February/054134.htmlhttp://secunia.com/advisories/43350http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.debian.org/security/2011/dsa-2224http://www.mandriva.com/security/advisories?name=MDVSA-2011:054http://www.securityfocus.com/bid/46439https://bugzilla.redhat.com/show_bug.cgi?id=677332https://exchange.xforce.ibmcloud.com/vulnerabilities/65534https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14117http://dbhole.wordpress.com/2011/02/15/icedtea-web-1-0-1-released/http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054115.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-February/054134.htmlhttp://secunia.com/advisories/43350http://security.gentoo.org/glsa/glsa-201406-32.xmlhttp://www.debian.org/security/2011/dsa-2224http://www.mandriva.com/security/advisories?name=MDVSA-2011:054http://www.securityfocus.com/bid/46439https://bugzilla.redhat.com/show_bug.cgi?id=677332https://exchange.xforce.ibmcloud.com/vulnerabilities/65534https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14117
2011-02-19
Published