Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.840712
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-1178-1)
Summary:The remote host is missing an update for the 'icedtea-web, openjdk-6, openjdk-6b18' package(s) announced via the USN-1178-1 advisory.
Description:Summary:
The remote host is missing an update for the 'icedtea-web, openjdk-6, openjdk-6b18' package(s) announced via the USN-1178-1 advisory.

Vulnerability Insight:
Omair Majid discovered that an unsigned Web Start application
or applet could determine the path to the cache directory used
to store downloaded class and jar files by querying class loader
properties. This could allow a remote attacker to discover a user's
name and home directory path. (CVE-2011-2513)

Omair Majid discovered that an unsigned Web Start application could
manipulate the content of the security warning dialog message to show
different file names in prompts. This could allow a remote attacker
to confuse a user into granting access to a different file than they
believe they are granting access to. This issue only affected Ubuntu
11.04. (CVE-2011-2514)

Affected Software/OS:
'icedtea-web, openjdk-6, openjdk-6b18' package(s) on Ubuntu 10.04, Ubuntu 10.10, Ubuntu 11.04.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2011-2513
http://icedtea.classpath.org/hg/release/icedtea-web-1.0/rev/b29fdd0f4d04
http://icedtea.classpath.org/hg/release/icedtea-web-1.1/rev/c7ce6c0e6227
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015171.html
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015170.html
RedHat Security Advisories: RHSA-2011:1100
http://rhn.redhat.com/errata/RHSA-2011-1100.html
http://securitytracker.com/id?1025854
http://ubuntu.com/usn/usn-1178-1
Common Vulnerability Exposure (CVE) ID: CVE-2011-2514
http://icedtea.classpath.org/hg/release/icedtea-web-1.0/rev/b99f9a9769e0
http://icedtea.classpath.org/hg/release/icedtea-web-1.1/rev/512de5d90388
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.