PT-2019-2899 · Icedtea+4 · Icedtea-Web+4

Imre Rad

·

Published

2019-07-31

·

Updated

2025-05-22

·

CVE-2019-10185

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions icedtea-web versions 1.7.2 and earlier icedtea-web versions 1.8.2 and earlier
Description The issue is related to a zip-slip attack during auto-extraction of a JAR file, which could allow an attacker to write files to arbitrary locations. This could potentially be used to replace the main running application and possibly break out of the sandbox. The vulnerability is also associated with incorrect restriction of the directory path name with limited access, allowing a remote attacker to write arbitrary files to the device's file system using a specially crafted file in formats such as .tar, .jar, .war, .cpio, .apk, .rar, or .7z.
Recommendations For icedtea-web versions 1.7.2 and earlier, update to a version later than 1.7.2 to resolve the issue. For icedtea-web versions 1.8.2 and earlier, update to a version later than 1.8.2 to resolve the issue. As a temporary workaround, consider disabling the auto-extraction of JAR files until a patch is available. Restrict access to the directory with limited access to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6401
BDU:2019-02868
CESA-2019_2003
CESA-2019_2004
CVE-2019-10185
DLA-1914-1
MGASA-2019-0242
OPENSUSE-SU-2019:1911-1
OPENSUSE-SU-2019_1911-1
OPENSUSE-SU-2022_1259-1
OPENSUSE-SU-2024:10855-1
RHSA-2019:2003
RHSA-2019:2004
RHSA-2019_2003
RHSA-2019_2004
SUSE-SU-2019:2033-1
SUSE-SU-2022:1259-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Icedtea-Web