Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2019-10185
Description:It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.
Test IDs: 1.3.6.1.4.1.25623.1.0.891914  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2019-10185
20191007 CVE-2019-10181, CVE-2019-10182, CVE-2019-10185: IcedTea-Web vulnerabilities leading to RCE
https://seclists.org/bugtraq/2019/Oct/5
GLSA-202107-51
https://security.gentoo.org/glsa/202107-51
[debian-lts-announce] 20190909 [SECURITY] [DLA 1914-1] icedtea-web security update
https://lists.debian.org/debian-lts-announce/2019/09/msg00008.html
http://packetstormsecurity.com/files/154748/IcedTeaWeb-Validation-Bypass-Directory-Traversal-Code-Execution.html
http://packetstormsecurity.com/files/154748/IcedTeaWeb-Validation-Bypass-Directory-Traversal-Code-Execution.html
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10185
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10185
https://github.com/AdoptOpenJDK/IcedTea-Web/issues/327
https://github.com/AdoptOpenJDK/IcedTea-Web/issues/327
https://github.com/AdoptOpenJDK/IcedTea-Web/pull/344
https://github.com/AdoptOpenJDK/IcedTea-Web/pull/344
openSUSE-SU-2019:1911
http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00045.html




© 1998-2025 E-Soft Inc. All rights reserved.