CVE-2010-4351
Summary
| CVE | CVE-2010-4351 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-01-20 19:00:00 UTC |
| Updated | 2023-02-13 04:28:00 UTC |
| Description | The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPermission method instead of throwing an exception in certain circumstances, which might allow context-dependent attackers to bypass the intended security policy by creating instances of ClassLoader. |
Risk And Classification
Problem Types: CWE-264
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Icedtea | 1.7 | All | All | All |
| Application | Redhat | Icedtea | 1.7.1 | All | All | All |
| Application | Redhat | Icedtea | 1.7.2 | All | All | All |
| Application | Redhat | Icedtea | 1.7.3 | All | All | All |
| Application | Redhat | Icedtea | 1.7.4 | All | All | All |
| Application | Redhat | Icedtea | 1.7.5 | All | All | All |
| Application | Redhat | Icedtea | 1.7.6 | All | All | All |
| Application | Redhat | Icedtea | 1.8 | All | All | All |
| Application | Redhat | Icedtea | 1.8.1 | All | All | All |
| Application | Redhat | Icedtea | 1.8.2 | All | All | All |
| Application | Redhat | Icedtea | 1.8.3 | All | All | All |
| Application | Redhat | Icedtea | 1.9 | All | All | All |
| Application | Redhat | Icedtea | 1.9.1 | All | All | All |
| Application | Redhat | Icedtea | 1.9.2 | All | All | All |
| Application | Redhat | Icedtea | 1.9.3 | All | All | All |
| Application | Redhat | Icedtea | 1.7 | All | All | All |
| Application | Redhat | Icedtea | 1.7.1 | All | All | All |
| Application | Redhat | Icedtea | 1.7.2 | All | All | All |
| Application | Redhat | Icedtea | 1.7.3 | All | All | All |
| Application | Redhat | Icedtea | 1.7.4 | All | All | All |
| Application | Redhat | Icedtea | 1.7.5 | All | All | All |
| Application | Redhat | Icedtea | 1.7.6 | All | All | All |
| Application | Redhat | Icedtea | 1.8 | All | All | All |
| Application | Redhat | Icedtea | 1.8.1 | All | All | All |
| Application | Redhat | Icedtea | 1.8.2 | All | All | All |
| Application | Redhat | Icedtea | 1.8.3 | All | All | All |
| Application | Redhat | Icedtea | 1.9 | All | All | All |
| Application | Redhat | Icedtea | 1.9.1 | All | All | All |
| Application | Redhat | Icedtea | 1.9.2 | All | All | All |
| Application | Redhat | Icedtea | 1.9.3 | All | All | All |
| Application | Sun | Openjdk | All | All | All | All |
| Application | Sun | Openjdk | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | MISC | access.redhat.com | |
| [SECURITY] Fedora 14 Update: java-1.6.0-openjdk-1.6.0.0-50.1.9.4.fc14 | FEDORA | lists.fedoraproject.org | |
| GNU/Andrew’s Blog » [SECURITY] IcedTea6 1.7.7, 1.8.4, 1.9.4 Released! | CONFIRM | blog.fuseyism.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| Fedora update for java-1.6.0-openjdk - Advisories - Community | SECUNIA | secunia.com | Vendor Advisory |
| Webmail - OVH | VUPEN | www.vupen.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| Zero Day Initiative | MISC | www.zerodayinitiative.com | |
| Ubuntu update for openjdk-6 - Advisories - Community | SECUNIA | secunia.com | |
| 70605 | OSVDB | osvdb.org | |
| USN-1055-1: OpenJDK vulnerabilities | Ubuntu | UBUNTU | www.ubuntu.com | |
| Security Advisories | Mandriva Linux | MANDRIVA | www.mandriva.com | |
| OpenJDK 'IcedTea' plugin JNLPSecurityManager Remote Code Execution Vulnerability | BID | www.securityfocus.com | |
| Ubuntu update for openjdk-6 - Secunia.com | SECUNIA | secunia.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Red Hat update for java-1.6.0-openjdk - Secunia.com | SECUNIA | secunia.com | |
| Gentoo Linux Documentation -- IcedTea JDK: Multiple vulnerabilities | GENTOO | security.gentoo.org | |
| Debian -- Security Information -- DSA-2224-1 openjdk-6 | DEBIAN | www.debian.org | |
| Support | REDHAT | www.redhat.com | |
| [SECURITY] Fedora 13 Update: java-1.6.0-openjdk-1.6.0.0-48.1.8.4.fc13 | FEDORA | lists.fedoraproject.org | |
| USN-1052-1: OpenJDK vulnerability | Ubuntu | UBUNTU | www.ubuntu.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | Vendor Advisory |
| CVE-2010-4351 - Red Hat Customer Portal | MISC | access.redhat.com | |
| Bug 663680 – CVE-2010-4351 IcedTea jnlp security manager bypass | CONFIRM | bugzilla.redhat.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.