PT-2011-1514 · Oracle+1 · Icedtea+1

Omair Majid

·

Published

2011-01-18

·

Updated

2023-02-13

·

CVE-2010-4351

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IcedTea versions 1.7 through 1.7.6 IcedTea versions 1.8 through 1.8.3 IcedTea versions 1.9 through 1.9.3
Description The issue allows context-dependent attackers to bypass the intended security policy by creating instances of ClassLoader. This might enable attackers to execute arbitrary code.
Recommendations For IcedTea versions 1.7 through 1.7.6, update to version 1.7.7 or later. For IcedTea versions 1.8 through 1.8.3, update to version 1.8.4 or later. For IcedTea versions 1.9 through 1.9.3, update to version 1.9.4 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2010-4351
DSA-2224-1
RHSA-2011:0176
RHSA-2011_0176
ZDI-11-014

Affected Products

Icedtea
Red Hat