Vulnerability Name: | CVE-2009-1896 (CCN-52522) | ||||||||||||
Assigned: | 2009-08-07 | ||||||||||||
Published: | 2009-08-07 | ||||||||||||
Updated: | 2009-08-26 | ||||||||||||
Summary: | The Java Web Start framework in IcedTea in OpenJDK before 1.6.0.0-20.b16.fc10 on Fedora 10, and before 1.6.0.0-27.b16.fc11 on Fedora 11, trusts an entire application when at least one of the listed jar files is trusted, which allows context-dependent attackers to execute arbitrary code without the untrusted-code restrictions via a crafted application, related to NetX. | ||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.6 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:TF/RC:C)
5.2 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:TF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2009-1896 Source: SECUNIA Type: Vendor Advisory 36162 Source: MANDRIVA Type: UNKNOWN MDVSA-2009:209 Source: CCN Type: OSVDB ID: 56972 OpenJDK IcedTea Java Web Start Framework JAR File Trust Weakness Privilege Escalation Source: CCN Type: BID-35922 Sun Java SE Multiple Security Vulnerabilities Source: CCN Type: USN-814-1 OpenJDK vulnerabilities Source: CCN Type: Red Hat Bugzilla Bug 512101 CVE-2009-1896 openjdk/netx grants privileges for signed jars to bundled unsigned jars Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=512101 Source: XF Type: UNKNOWN openjdk-icedtea-jws-code-execution(52522) Source: FEDORA Type: Vendor Advisory FEDORA-2009-8329 Source: FEDORA Type: UNKNOWN FEDORA-2009-8337 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |