IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which allows remote attackers to obtain sensitive information including (1) user.name, (2) user.home, and (3) java.home system properties, and other sensitive information such as installation directories.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2010-12-08T19:00:00
Updated: 2024-08-07T03:26:12.234Z
Reserved: 2010-10-08T00:00:00
Link: CVE-2010-3860
Vulnrichment
No data.
NVD
Status : Modified
Published: 2010-12-08T20:00:01.370
Modified: 2024-11-21T01:19:46.397
Link: CVE-2010-3860
Redhat