Back

HIGH

IcedTea multiple signers privilege escalation

Published Feb 18, 2011

Description

The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of "an inappropriate security descriptor."

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of the java-1.6.0-openjdk package as shipped with Red Hat Enterprise Linux 5 and 6.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 18, 2011
Updated Aug 6, 2024
Reserved Jan 31, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Feb 15, 2011