7.5

CVE-2011-0706

The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of "an inappropriate security descriptor."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Icedtea-web Version 1.0
Redhat ≫ Icedtea-web Version 1.0 Update pre
Redhat ≫ Icedtea-web Version 1.0.1 Update pre
Sun ≫ Jdk Version 1.6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.09% 0.86
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www.debian.org/security/2011/dsa-2224
http://www.mandriva.com/security/advisories?name=MDVSA-2011:054
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054115.html
http://lists.fedoraproject.org/pipermail/package-announce/2011-February/054134.html
http://secunia.com/advisories/43350
Vendor Advisory
http://dbhole.wordpress.com/2011/02/15/icedtea-web-1-0-1-released/
Patch
http://www.securityfocus.com/bid/46439
https://bugzilla.redhat.com/show_bug.cgi?id=677332
https://exchange.xforce.ibmcloud.com/vulnerabilities/65534
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14117