[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2011-2513Date: (C)2014-05-11   (M)2024-04-19


The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to obtain the username and full path of the home and cache directories by accessing properties of the ClassLoader.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1025854
RHSA-2011:1100
USN-1178-1
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015171.html
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015170.html
http://icedtea.classpath.org/hg/release/icedtea-web-1.0/rev/b29fdd0f4d04
http://icedtea.classpath.org/hg/release/icedtea-web-1.1/rev/c7ce6c0e6227
https://bugzilla.redhat.com/show_bug.cgi?id=718164

CPE    21
cpe:/a:redhat:icedtea-web
cpe:/a:redhat:icedtea-web:1.1
cpe:/a:redhat:icedtea-web:1.0
cpe:/a:redhat:icedtea-web:1.0.2
...
CWE    1
CWE-200
OVAL    6
oval:org.secpod.oval:def:700563
oval:org.secpod.oval:def:500101
oval:org.secpod.oval:def:1503429
oval:org.secpod.oval:def:102836
...

© SecPod Technologies