CVE Vulnerabilities

CVE-2011-0706

Published: Feb 19, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
7.5 IMPORTANT
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of an inappropriate security descriptor.

Affected Software

NameVendorStart VersionEnd Version
Icedtea-webRedhat1.0 (including)1.0 (including)
Icedtea-webRedhat1.0-pre (including)1.0-pre (including)
Icedtea-webRedhat1.0.1-pre (including)1.0.1-pre (including)
Openjdk-6Ubuntuhardy*
Openjdk-6Ubuntukarmic*
Openjdk-6Ubuntulucid*
Openjdk-6Ubuntumaverick*
Openjdk-6Ubuntuupstream*
Openjdk-6b18Ubuntudevel*
Openjdk-6b18Ubuntukarmic*
Openjdk-6b18Ubuntulucid*
Openjdk-6b18Ubuntumaverick*
Openjdk-6b18Ubuntunatty*
Openjdk-6b18Ubuntuoneiric*
Openjdk-6b18Ubuntuupstream*

References