CVE-2011-2514
published 2014-05-14CVE-2011-2514: The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4…
PriorityP432medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.40%
82.1th percentile
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to trick victims into granting access to local files by modifying the content of the Java Web Start Security Warning dialog box to represent a different filename than the file for which access will be granted.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | icedtea-web | < icedtea-web 1.1-1 (bookworm) | icedtea-web 1.1-1 (bookworm) |
| redhat | icedtea-web | <= 1.0.3 | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | — | — |
| redhat | icedtea-web | >= 0 < 1.1-1 | 1.1-1 |
| redhat | icedtea-web | >= 0 < 1.1-1 | 1.1-1 |
| redhat | icedtea-web | >= 0 < 1.1-1 | 1.1-1 |
| redhat | icedtea-web | >= 0 < 1.1-1 | 1.1-1 |
| redhat | icedtea6 | <= 1.8.8 | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
| redhat | icedtea6 | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
IcedTea-Web, OpenJDK 6 vulnerabilities
vendor_ubuntu·2011-07-27·CVSS 5.0
CVE-2011-2513 [MEDIUM] IcedTea-Web, OpenJDK 6 vulnerabilities
Title: IcedTea-Web, OpenJDK 6 vulnerabilities
Summary: An attacker could discover a user's name or confuse a user into granting
unintended access to files.
Omair Majid discovered that an unsigned Web Start application
or applet could determine the path to the cache directory used
to store downloaded class and jar files by querying class loader
properties. This could allow a remote attacker to discover a user's
name and home directory path. (CVE-2011-2513)
Omair Majid discovered that an unsigned Web Start application could
manipulate the content of the security warning dialog message to show
different file names in prompts. This could allow a remote attacker
to confuse a user into granting access to a different file than they
believe they are granting access to. This issue only affected
Red Hat
icedtea-web: Java Web Start security warning dialog manipulation
vendor_redhat·2011-07-20·CVSS 6.8
CVE-2011-2514 [MEDIUM] icedtea-web: Java Web Start security warning dialog manipulation
icedtea-web: Java Web Start security warning dialog manipulation
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to trick victims into granting access to local files by modifying the content of the Java Web Start Security Warning dialog box to represent a different filename than the file for which access will be granted.
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 5) - Not affected
Package: java-1.6.0-openjdk (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2011-2514: icedtea-web - The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x befo...
vendor_debian·2011·CVSS 6.8
CVE-2011-2514 [MEDIUM] CVE-2011-2514: icedtea-web - The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x befo...
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to trick victims into granting access to local files by modifying the content of the Java Web Start Security Warning dialog box to represent a different filename than the file for which access will be granted.
Scope: local
bookworm: resolved (fixed in 1.1-1)
bullseye: resolved (fixed in 1.1-1)
forky: resolved (fixed in 1.1-1)
sid: resolved (fixed in 1.1-1)
trixie: resolved (fixed in 1.1-1)
GHSA
GHSA-mfx6-3x7c-57wf: The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1
ghsa_unreviewed·2022-05-17
CVE-2011-2514 [MEDIUM] GHSA-mfx6-3x7c-57wf: The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to trick victims into granting access to local files by modifying the content of the Java Web Start Security Warning dialog box to represent a different filename than the file for which access will be granted.
OSV
CVE-2011-2514: The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1
osv·2014-05-14·CVSS 6.8
CVE-2011-2514 [MEDIUM] CVE-2011-2514: The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to trick victims into granting access to local files by modifying the content of the Java Web Start Security Warning dialog box to represent a different filename than the file for which access will be granted.
No detection rules found.
Bugzilla
CVE-2011-2513 CVE-2011-2514 icedtea-web: multiple security issues [fedora-15]
bugzilla·2011-07-20·CVSS 5.0
CVE-2011-2513 [MEDIUM] CVE-2011-2513 CVE-2011-2514 icedtea-web: multiple security issues [fedora-15]
CVE-2011-2513 CVE-2011-2514 icedtea-web: multiple security issues [fedora-15]
fedora-15 tracking bug for icedtea-web: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
This message is a notice that Fedora 15 is now at end of life. Fedora
has stopped maintaining and issuing updates for Fedora 15. It is
Fedora's policy to close all bug reports from releases that are no
longer maintained. At this time, all open bugs with a Fedora 'version'
of '15' have been closed as WONTFIX.
(Please note: Our normal process is to give advanced warning of this
occurring, but we forgot to do that. A thousand apologies.)
Package Mainta
Bugzilla
CVE-2011-2514 icedtea-web: Java Web Start security warning dialog manipulation
bugzilla·2011-07-01·CVSS 6.8
CVE-2011-2514 [MEDIUM] CVE-2011-2514 icedtea-web: Java Web Start security warning dialog manipulation
CVE-2011-2514 icedtea-web: Java Web Start security warning dialog manipulation
Omair Majid discovered a flaw in the JNLP (Java Network Launching Protocol) implementation used in IcedTea-web. An unsigned Java Web Start application could use this flaw to manipulate content of the Security Warning dialog to show different file name than the one access to which was requested by the applications. This could confuse user to grant unintended access to local files.
Note: This issue does not affect JNLP implementation as currently used in IcedTea, as it contains older version of the code that does not include file name in the access request prompt. Instead the prompt says "The application has requested (read|write) access to a file on the machine. Do you want to allow this action?", which does no
http://icedtea.classpath.org/hg/release/icedtea-web-1.0/rev/b99f9a9769e0http://icedtea.classpath.org/hg/release/icedtea-web-1.1/rev/512de5d90388http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015170.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015171.htmlhttp://rhn.redhat.com/errata/RHSA-2011-1100.htmlhttp://securitytracker.com/id?1025854http://ubuntu.com/usn/usn-1178-1https://bugzilla.redhat.com/show_bug.cgi?id=718170http://icedtea.classpath.org/hg/release/icedtea-web-1.0/rev/b99f9a9769e0http://icedtea.classpath.org/hg/release/icedtea-web-1.1/rev/512de5d90388http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015170.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015171.htmlhttp://rhn.redhat.com/errata/RHSA-2011-1100.htmlhttp://securitytracker.com/id?1025854http://ubuntu.com/usn/usn-1178-1https://bugzilla.redhat.com/show_bug.cgi?id=718170
2014-05-14
Published