Description
It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1914-1 | icedtea-web security update |
EUVD |
EUVD-2019-2210 | It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user. |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T22:10:09.992Z
Reserved: 2019-03-27T00:00:00.000Z
Link: CVE-2019-10182
No data.
Status : Modified
Published: 2019-07-31T22:15:12.183
Modified: 2024-11-21T04:18:36.017
Link: CVE-2019-10182
OpenCVE Enrichment
No data.
Debian DLA
EUVD