It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.
References
Configurations
History
No history.
Information
Published : 2019-07-31 23:15
Updated : 2024-11-21 04:18
NVD link : CVE-2019-10181
Mitre link : CVE-2019-10181
CVE.ORG link : CVE-2019-10181
JSON object : View
Products Affected
icedtea-web_project
- icedtea-web
debian
- debian_linux
opensuse
- leap
CWE
CWE-345
Insufficient Verification of Data Authenticity