Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.70897
Kategorie:Ubuntu Local Security Checks
Titel:Ubuntu USN-1178-1 (icedtea-netx)
Zusammenfassung:NOSUMMARY
Beschreibung:Description:
The remote host is missing an update to icedtea-netx
announced via advisory USN-1178-1.

Details:

Omair Majid discovered that an unsigned Web Start application
or applet could determine the path to the cache directory used
to store downloaded class and jar files by querying class loader
properties. This could allow a remote attacker to discover a user's
name and home directory path. (CVE-2011-2513)

Omair Majid discovered that an unsigned Web Start application could
manipulate the content of the security warning dialog message to show
different file names in prompts. This could allow a remote attacker
to confuse a user into granting access to a different file than they
believe they are granting access to. This issue only affected Ubuntu
11.04. (CVE-2011-2514)

Solution:
The problem can be corrected by updating your system to the following
package versions:

Ubuntu 11.04:
icedtea-netx 1.1.1-0ubuntu1~
11.04.1
icedtea-plugin 1.1.1-0ubuntu1~
11.04.1

Ubuntu 10.10:
icedtea6-plugin 6b20-1.9.9-0ubuntu1~
10.10.2

Ubuntu 10.04 LTS:
icedtea6-plugin 6b20-1.9.9-0ubuntu1~
10.04.2

http://www.securityspace.com/smysecure/catid.html?in=USN-1178-1

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2011-2513
http://icedtea.classpath.org/hg/release/icedtea-web-1.0/rev/b29fdd0f4d04
http://icedtea.classpath.org/hg/release/icedtea-web-1.1/rev/c7ce6c0e6227
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015171.html
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2011-July/015170.html
RedHat Security Advisories: RHSA-2011:1100
http://rhn.redhat.com/errata/RHSA-2011-1100.html
http://securitytracker.com/id?1025854
http://ubuntu.com/usn/usn-1178-1
Common Vulnerability Exposure (CVE) ID: CVE-2011-2514
http://icedtea.classpath.org/hg/release/icedtea-web-1.0/rev/b99f9a9769e0
http://icedtea.classpath.org/hg/release/icedtea-web-1.1/rev/512de5d90388
CopyrightCopyright (c) 2012 E-Soft Inc. http://www.securityspace.com

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.