icedtea-web: unsigned code injection in a signed JAR file
Published Jul 31, 2019
8.1
HIGHCVSS 3.1
EPSS 1.17%
Description
It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.
Affected products
-
Affected
- affects up to and including 1.7.2 and 1.8.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| IcedTea | Icedtea-Web | unknown | Affected
|
Configuration 1
- ≤ 1.7.2
- 1.8.2
Configuration 2
- 8.0
No data.
Red Hat Enterprise Linux 7
icedtea-web-0:1.7.1-2.el7_6
Fixed · RHSA-2019:2003
Red Hat Enterprise Linux 8
icedtea-web-0:1.7.1-17.el8_0
Fixed · RHSA-2019:2004
Red Hat Enterprise Linux 6
icedtea-web
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | icedtea-web-0:1.7.1-2.el7_6 | Fixed | RHSA-2019:2003 |
| Red Hat Enterprise Linux 8 | icedtea-web-0:1.7.1-17.el8_0 | Fixed | RHSA-2019:2004 |
| Red Hat Enterprise Linux 6 | icedtea-web | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00045.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://packetstormsecurity.com/files/154748/IcedTeaWeb-Validation-Bypass-Directory-Traversal-Code-Execution.html x_refsource_MISCThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2019-10181 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1725928 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10181 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-2209 Advisory
- https://github.com/AdoptOpenJDK/IcedTea-Web/issues/327 x_refsource_CONFIRMThird Party Advisory
- https://github.com/AdoptOpenJDK/IcedTea-Web/pull/344 x_refsource_CONFIRMPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00008.html mailing-listx_refsource_MLISTThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-10181
- https://seclists.org/bugtraq/2019/Oct/5 mailing-listx_refsource_BUGTRAQMailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202107-51 vendor-advisoryx_refsource_GENTOOPatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-10181
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data