Vulnerability Description
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to trick victims into granting access to local files by modifying the content of the Java Web Start Security Warning dialog box to represent a different filename than the file for which access will be granted.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Icedtea-Web | <= 1.0.3 |
| Redhat | Icedtea6 | <= 1.8.8 |
Related Weaknesses (CWE)
References
- http://icedtea.classpath.org/hg/release/icedtea-web-1.0/rev/b99f9a9769e0
- http://icedtea.classpath.org/hg/release/icedtea-web-1.1/rev/512de5d90388
- http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015170.html
- http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015171.htmlPatchVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2011-1100.html
- http://securitytracker.com/id?1025854
- http://ubuntu.com/usn/usn-1178-1Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=718170
- http://icedtea.classpath.org/hg/release/icedtea-web-1.0/rev/b99f9a9769e0
- http://icedtea.classpath.org/hg/release/icedtea-web-1.1/rev/512de5d90388
- http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015170.html
- http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015171.htmlPatchVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2011-1100.html
- http://securitytracker.com/id?1025854
- http://ubuntu.com/usn/usn-1178-1Patch
FAQ
What is CVE-2011-2514?
CVE-2011-2514 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to trick victims...
How severe is CVE-2011-2514?
CVE-2011-2514 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-2514?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Icedtea-Web, Redhat Icedtea6.