IcedTea6 and IcedTea-Web Information Disclosure and Security Bypass Vulnerabilities.
BID:48829
Info
IcedTea6 and IcedTea-Web Information Disclosure and Security Bypass Vulnerabilities.
| Bugtraq ID: | 48829 |
| Class: | Unknown |
| CVE: |
CVE-2011-2513 CVE-2011-2514 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2011 12:00AM |
| Updated: | Apr 13 2015 09:23PM |
| Credit: | Omair Majid |
| Vulnerable: |
Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Ubuntu Ubuntu Linux 10.10 powerpc Ubuntu Ubuntu Linux 10.10 i386 Ubuntu Ubuntu Linux 10.10 ARM Ubuntu Ubuntu Linux 10.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Red Hat Enterprise Linux Workstation Optional 6 Red Hat Enterprise Linux Workstation 6 Red Hat Enterprise Linux Server Optional 6 Red Hat Enterprise Linux Server 6 Red Hat Enterprise Linux HPC Node Optional 6 Red Hat Enterprise Linux HPC Node 6 Red Hat Enterprise Linux Desktop Optional 6 Red Hat Enterprise Linux Desktop 6 IcedTea IcedTea6 1.9.8 IcedTea IcedTea6 1.8.8 IcedTea IcedTea-Web 1.1 IcedTea IcedTea-Web 1.0.5 |
| Not Vulnerable: |
IcedTea IcedTea6 1.9.9 IcedTea IcedTea6 1.8.9 IcedTea IcedTea-Web 1.1.1 IcedTea IcedTea-Web 1.0.4 |
Exploit / POC
IcedTea6 and IcedTea-Web Information Disclosure and Security Bypass Vulnerabilities.
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
References
IcedTea6 and IcedTea-Web Information Disclosure and Security Bypass Vulnerabilities.
References:
References:
- [SECURITY] IcedTea6 1.8.9 & 1.9.9 Released! (OpenJDK)
- CVE-2011-2513 icedtea, icedtea-web: home directory path disclosure to untrusted (Red Hat)
- CVE-2011-2514 icedtea-web: Java Web Start security warning dialog manipulation (Red Hat)
- IcedTea Homepage (IcedTea)
- IcedTea-Web 1.0.4 and 1.1.1 (security releases) released (OpenJDK)