CVE Vulnerabilities

CVE-2011-0706

Published: Feb 19, 2011 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
7.5 IMPORTANT
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of an inappropriate security descriptor.

Affected Software

Name Vendor Start Version End Version
Icedtea-web Redhat 1.0 (including) 1.0 (including)
Icedtea-web Redhat 1.0-pre (including) 1.0-pre (including)
Icedtea-web Redhat 1.0.1-pre (including) 1.0.1-pre (including)
Openjdk-6 Ubuntu hardy *
Openjdk-6 Ubuntu karmic *
Openjdk-6 Ubuntu lucid *
Openjdk-6 Ubuntu maverick *
Openjdk-6 Ubuntu upstream *
Openjdk-6b18 Ubuntu devel *
Openjdk-6b18 Ubuntu karmic *
Openjdk-6b18 Ubuntu lucid *
Openjdk-6b18 Ubuntu maverick *
Openjdk-6b18 Ubuntu natty *
Openjdk-6b18 Ubuntu oneiric *
Openjdk-6b18 Ubuntu upstream *

References