CVE-2011-2513
published 2014-05-14CVE-2011-2513: The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4…
PriorityP426medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.50%
82.9th percentile
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to obtain the username and full path of the home and cache directories by accessing properties of the ClassLoader.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | icedtea-web | < icedtea-web 1.1.2-1 (bookworm) | icedtea-web 1.1.2-1 (bookworm) |
| redhat | icedtea-web | <= 1.0.3 | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | >= 0 < 1.1.2-1 | 1.1.2-1 |
| redhat | icedtea-web | >= 0 < 1.1.2-1 | 1.1.2-1 |
| redhat | icedtea-web | >= 0 < 1.1.2-1 | 1.1.2-1 |
| redhat | icedtea-web | >= 0 < 1.1.2-1 | 1.1.2-1 |
| redhat | icedtea6 | <= 1.8.8 | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
IcedTea-Web, OpenJDK 6 vulnerabilities
vendor_ubuntu·2011-07-27·CVSS 5.0
CVE-2011-2513 [MEDIUM] IcedTea-Web, OpenJDK 6 vulnerabilities
Title: IcedTea-Web, OpenJDK 6 vulnerabilities
Summary: An attacker could discover a user's name or confuse a user into granting
unintended access to files.
Omair Majid discovered that an unsigned Web Start application
or applet could determine the path to the cache directory used
to store downloaded class and jar files by querying class loader
properties. This could allow a remote attacker to discover a user's
name and home directory path. (CVE-2011-2513)
Omair Majid discovered that an unsigned Web Start application could
manipulate the content of the security warning dialog message to show
different file names in prompts. This could allow a remote attacker
to confuse a user into granting access to a different file than they
believe they are granting access to. This issue only affected
Red Hat
icedtea-web: home directory path disclosure to untrusted applications
vendor_redhat·2011-07-20·CVSS 5.0
CVE-2011-2513 [MEDIUM] icedtea-web: home directory path disclosure to untrusted applications
icedtea-web: home directory path disclosure to untrusted applications
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to obtain the username and full path of the home and cache directories by accessing properties of the ClassLoader.
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2011-2513: icedtea-web - The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x befo...
vendor_debian·2011·CVSS 5.0
CVE-2011-2513 [MEDIUM] CVE-2011-2513: icedtea-web - The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x befo...
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to obtain the username and full path of the home and cache directories by accessing properties of the ClassLoader.
Scope: local
bookworm: resolved (fixed in 1.1.2-1)
bullseye: resolved (fixed in 1.1.2-1)
forky: resolved (fixed in 1.1.2-1)
sid: resolved (fixed in 1.1.2-1)
trixie: resolved (fixed in 1.1.2-1)
GHSA
GHSA-pphc-5pp2-xfm2: The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1
ghsa_unreviewed·2022-05-17
CVE-2011-2513 [MEDIUM] CWE-200 GHSA-pphc-5pp2-xfm2: The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to obtain the username and full path of the home and cache directories by accessing properties of the ClassLoader.
OSV
CVE-2011-2513: The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1
osv·2014-05-14·CVSS 5.0
CVE-2011-2513 [MEDIUM] CVE-2011-2513: The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to obtain the username and full path of the home and cache directories by accessing properties of the ClassLoader.
No detection rules found.
Bugzilla
CVE-2011-2513 CVE-2011-2514 icedtea-web: multiple security issues [fedora-15]
bugzilla·2011-07-20·CVSS 5.0
CVE-2011-2513 [MEDIUM] CVE-2011-2513 CVE-2011-2514 icedtea-web: multiple security issues [fedora-15]
CVE-2011-2513 CVE-2011-2514 icedtea-web: multiple security issues [fedora-15]
fedora-15 tracking bug for icedtea-web: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
This message is a notice that Fedora 15 is now at end of life. Fedora
has stopped maintaining and issuing updates for Fedora 15. It is
Fedora's policy to close all bug reports from releases that are no
longer maintained. At this time, all open bugs with a Fedora 'version'
of '15' have been closed as WONTFIX.
(Please note: Our normal process is to give advanced warning of this
occurring, but we forgot to do that. A thousand apologies.)
Package Mainta
Bugzilla
CVE-2011-2513 icedtea, icedtea-web: home directory path disclosure to untrusted applications [fedora-14]
bugzilla·2011-07-20·CVSS 5.0
CVE-2011-2513 [MEDIUM] CVE-2011-2513 icedtea, icedtea-web: home directory path disclosure to untrusted applications [fedora-14]
CVE-2011-2513 icedtea, icedtea-web: home directory path disclosure to untrusted applications [fedora-14]
fedora-14 tracking bug for java-1.6.0-openjdk: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
F14 is EOL, fixed in icedtea-web in newer Fedora.
Bugzilla
CVE-2011-2513 icedtea, icedtea-web: home directory path disclosure to untrusted applications
bugzilla·2011-07-01·CVSS 5.0
CVE-2011-2513 [MEDIUM] CVE-2011-2513 icedtea, icedtea-web: home directory path disclosure to untrusted applications
CVE-2011-2513 icedtea, icedtea-web: home directory path disclosure to untrusted applications
Omair Majid discovered an information disclosure flaw in the JNLP (Java Network Launching Protocol) implementation used in IcedTea and IcedTea-web. An unsigned Java Web Start application or Java Applet could use this flaw to determine a path to the cache directory (/home//.netx/cache/) used to store downloaded jars for Web Start application or Applet by querying class's ClassLoader properties. This discloses full path to user's home directory on the local system and user's login name.
Discussion:
Public now via upstream release:
IcedTea-Web 1.0.4 and 1.1.1
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015171.html
IcedTea6 1.8.9 and 1.9.9
http://mail.openjdk.java.net/pipermail
http://icedtea.classpath.org/hg/release/icedtea-web-1.0/rev/b29fdd0f4d04http://icedtea.classpath.org/hg/release/icedtea-web-1.1/rev/c7ce6c0e6227http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015170.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015171.htmlhttp://rhn.redhat.com/errata/RHSA-2011-1100.htmlhttp://securitytracker.com/id?1025854http://ubuntu.com/usn/usn-1178-1https://bugzilla.redhat.com/show_bug.cgi?id=718164http://icedtea.classpath.org/hg/release/icedtea-web-1.0/rev/b29fdd0f4d04http://icedtea.classpath.org/hg/release/icedtea-web-1.1/rev/c7ce6c0e6227http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015170.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015171.htmlhttp://rhn.redhat.com/errata/RHSA-2011-1100.htmlhttp://securitytracker.com/id?1025854http://ubuntu.com/usn/usn-1178-1https://bugzilla.redhat.com/show_bug.cgi?id=718164
2014-05-14
Published