CVE-2011-2513
14.05.2014, 00:55
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to obtain the username and full path of the home and cache directories by accessing properties of the ClassLoader.Enginsight
| Vendor | Product | Version |
|---|---|---|
| redhat | icedtea-web | 𝑥 ≤ 1.0.3 |
| redhat | icedtea-web | 1.0 |
| redhat | icedtea-web | 1.0.1 |
| redhat | icedtea-web | 1.0.2 |
| redhat | icedtea-web | 1.1 |
| redhat | icedtea6 | 𝑥 ≤ 1.8.8 |
| redhat | icedtea6 | 1.8 |
| redhat | icedtea6 | 1.8.1 |
| redhat | icedtea6 | 1.8.2 |
| redhat | icedtea6 | 1.8.3 |
| redhat | icedtea6 | 1.8.4 |
| redhat | icedtea6 | 1.8.5 |
| redhat | icedtea6 | 1.8.6 |
| redhat | icedtea6 | 1.8.7 |
| redhat | icedtea6 | 1.9.1 |
| redhat | icedtea6 | 1.9.2 |
| redhat | icedtea6 | 1.9.3 |
| redhat | icedtea6 | 1.9.4 |
| redhat | icedtea6 | 1.9.5 |
| redhat | icedtea6 | 1.9.6 |
| redhat | icedtea6 | 1.9.7 |
| redhat | icedtea6 | 1.9.8 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| icedtea-web |
| ||||||||||
| openjdk-6 |
| ||||||||||
| openjdk-6b18 |
| ||||||||||
| sun-java5 |
| ||||||||||
| sun-java6 |
|
Common Weakness Enumeration
References