[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-3860Date: (C)2010-12-08   (M)2023-12-22


IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which allows remote attackers to obtain sensitive information including (1) user.name, (2) user.home, and (3) java.home system properties, and other sensitive information such as installation directories.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECUNIA-42412
SECUNIA-42417
SECUNIA-43085
BID-45114
ADV-2010-3090
ADV-2010-3108
ADV-2011-0215
FEDORA-2010-18393
GLSA-201406-32
RHSA-2011:0176
SUSE-SR:2010:023
USN-1024-1
http://blog.fuseyism.com/index.php/2010/11/24/icedtea6-176-183-and-192-released/
http://icedtea.classpath.org/hg/release/icedtea6-1.9/rev/9aa0018d8c28
https://bugzilla.redhat.com/show_bug.cgi?id=645843

CWE    1
CWE-200
OVAL    5
oval:org.secpod.oval:def:700081
oval:org.secpod.oval:def:103283
oval:org.secpod.oval:def:201481
oval:org.secpod.oval:def:500252
...

© SecPod Technologies