Back to search
CVE-2011-2514
Published: May 14, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to trick victims into granting access to local files by modifying the content of the Java Web Start Security Warning dialog box to represent a different filename than the file for which access will be granted.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[distro-pkg-dev] 20110720 IcedTea-Web 1.0.4 and 1.1.1 (security releases) released
mailing-list
x_refsource_MLIST
USN-1178-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2011:1100
vendor-advisory
x_refsource_REDHAT
[distro-pkg-dev] 20110720 [SECURITY] IcedTea6 1.8.9 & 1.9.9 Released!
mailing-list
x_refsource_MLIST
https://bugzilla.redhat.com/show_bug.cgi?id=718170
x_refsource_CONFIRM
1025854
vdb-entry
x_refsource_SECTRACK
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now