CVE-2019-10185
Summary
| CVE | CVE-2019-10185 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-31 23:15:00 UTC |
| Updated | 2023-02-12 23:33:00 UTC |
| Description | It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1724989 – (CVE-2019-10185) CVE-2019-10185 icedtea-web: directory traversal in the nested jar auto-extraction leading to arbitrary file overwrite |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| fixing CVEs 2019- 10181, 10182, 10185 found by Imre Rad - master by judovana · Pull Request #344 · AdoptOpenJDK/IcedTea-Web · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| Bugtraq: CVE-2019-10181, CVE-2019-10182, CVE-2019-10185: IcedTea-Web vulnerabilities leading to RCE |
BUGTRAQ |
seclists.org |
|
| [SECURITY] [DLA 1914-1] icedtea-web security update |
MLIST |
lists.debian.org |
|
| [security-announce] openSUSE-SU-2019:1911-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| upcoming security release 31.7.2019 · Issue #327 · AdoptOpenJDK/IcedTea-Web · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| CVE-2019-10185 - Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| 1724989 – (CVE-2019-10185) CVE-2019-10185 icedtea-web: directory traversal in the nested jar auto-extraction leading to arbitrary file overwrite |
MISC |
bugzilla.redhat.com |
|
| IcedTeaWeb: Multiple vulnerabilities (GLSA 202107-51) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| IcedTeaWeb Validation Bypass / Directory Traversal / Code Execution ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| Red Hat Customer Portal |
MISC |
access.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377125 Alibaba Cloud Linux Security Update for icedtea-web (ALINUX3-SA-2022:0037)
- 710044 Gentoo Linux IcedTeaWeb Multiple Vulnerabilities (GLSA 202107-51)
- 753209 SUSE Enterprise Linux Security Update for icedtea-web (SUSE-SU-2022:1259-1)