PT-2019-2900 · Icedtea+4 · Icedtea-Web+4

Imre Rad

·

Published

2019-07-31

·

Updated

2025-05-22

·

CVE-2019-10182

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:P
Name of the Vulnerable Software and Affected Versions IcedTea-Web versions 1.7.2 and 1.8.2
Description The issue is related to the improper sanitization of paths from jar/ elements in JNLP files. This could allow an attacker to trick a victim into running a specially crafted application, potentially leading to the upload of arbitrary files to arbitrary locations on the user's system. The vulnerability can be exploited by a remote attacker using a specially crafted application to write arbitrary files to the device's file system.
Recommendations For IcedTea-Web versions 1.7.2 and 1.8.2, consider disabling the processing of JNLP files until a patch is available to prevent the exploitation of this issue. Restrict access to the jar/ elements in JNLP files to minimize the risk of arbitrary file uploads. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Path traversal

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6401
BDU:2019-02869
CESA-2019_2003
CESA-2019_2004
CVE-2019-10182
DLA-1914-1
MGASA-2019-0242
OPENSUSE-SU-2019:1911-1
OPENSUSE-SU-2019_1911-1
OPENSUSE-SU-2022_1259-1
OPENSUSE-SU-2024:10855-1
RHSA-2019:2003
RHSA-2019:2004
RHSA-2019_2003
RHSA-2019_2004
SUSE-SU-2019:2033-1
SUSE-SU-2022:1259-1

Affected Products

Alt Linux
Centos
Icedtea-Web
Red Hat
Suse