CVE-2010-3860

IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which allows remote attackers to obtain sensitive information including (1) user.name, (2) user.home, and (3) java.home system properties, and other sensitive information such as installation directories.
References
Link Resource
http://blog.fuseyism.com/index.php/2010/11/24/icedtea6-176-183-and-192-released/
http://icedtea.classpath.org/hg/release/icedtea6-1.9/rev/9aa0018d8c28 Patch
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051711.html
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html
http://secunia.com/advisories/42412 Vendor Advisory
http://secunia.com/advisories/42417 Vendor Advisory
http://secunia.com/advisories/43085
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www.redhat.com/support/errata/RHSA-2011-0176.html
http://www.securityfocus.com/bid/45114
http://www.ubuntu.com/usn/USN-1024-1
http://www.vupen.com/english/advisories/2010/3090 Vendor Advisory
http://www.vupen.com/english/advisories/2010/3108 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0215
https://bugzilla.redhat.com/show_bug.cgi?id=645843 Patch
http://blog.fuseyism.com/index.php/2010/11/24/icedtea6-176-183-and-192-released/
http://icedtea.classpath.org/hg/release/icedtea6-1.9/rev/9aa0018d8c28 Patch
http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051711.html
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html
http://secunia.com/advisories/42412 Vendor Advisory
http://secunia.com/advisories/42417 Vendor Advisory
http://secunia.com/advisories/43085
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://www.redhat.com/support/errata/RHSA-2011-0176.html
http://www.securityfocus.com/bid/45114
http://www.ubuntu.com/usn/USN-1024-1
http://www.vupen.com/english/advisories/2010/3090 Vendor Advisory
http://www.vupen.com/english/advisories/2010/3108 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0215
https://bugzilla.redhat.com/show_bug.cgi?id=645843 Patch
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:icedtea:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea:1.5:rc1:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea:1.5:rc2:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea:1.5:rc3:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea:1.6:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea:1.7:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea:1.8:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea:1.8.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:icedtea:1.9:*:*:*:*:*:*:*

History

21 Nov 2024, 01:19

Type Values Removed Values Added
References () http://blog.fuseyism.com/index.php/2010/11/24/icedtea6-176-183-and-192-released/ - () http://blog.fuseyism.com/index.php/2010/11/24/icedtea6-176-183-and-192-released/ -
References () http://icedtea.classpath.org/hg/release/icedtea6-1.9/rev/9aa0018d8c28 - Patch () http://icedtea.classpath.org/hg/release/icedtea6-1.9/rev/9aa0018d8c28 - Patch
References () http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051711.html - () http://lists.fedoraproject.org/pipermail/package-announce/2010-December/051711.html -
References () http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html - () http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00000.html -
References () http://secunia.com/advisories/42412 - Vendor Advisory () http://secunia.com/advisories/42412 - Vendor Advisory
References () http://secunia.com/advisories/42417 - Vendor Advisory () http://secunia.com/advisories/42417 - Vendor Advisory
References () http://secunia.com/advisories/43085 - () http://secunia.com/advisories/43085 -
References () http://security.gentoo.org/glsa/glsa-201406-32.xml - () http://security.gentoo.org/glsa/glsa-201406-32.xml -
References () http://www.redhat.com/support/errata/RHSA-2011-0176.html - () http://www.redhat.com/support/errata/RHSA-2011-0176.html -
References () http://www.securityfocus.com/bid/45114 - () http://www.securityfocus.com/bid/45114 -
References () http://www.ubuntu.com/usn/USN-1024-1 - () http://www.ubuntu.com/usn/USN-1024-1 -
References () http://www.vupen.com/english/advisories/2010/3090 - Vendor Advisory () http://www.vupen.com/english/advisories/2010/3090 - Vendor Advisory
References () http://www.vupen.com/english/advisories/2010/3108 - Vendor Advisory () http://www.vupen.com/english/advisories/2010/3108 - Vendor Advisory
References () http://www.vupen.com/english/advisories/2011/0215 - () http://www.vupen.com/english/advisories/2011/0215 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=645843 - Patch () https://bugzilla.redhat.com/show_bug.cgi?id=645843 - Patch

Information

Published : 2010-12-08 20:00

Updated : 2024-11-21 01:19


NVD link : CVE-2010-3860

Mitre link : CVE-2010-3860

CVE.ORG link : CVE-2010-3860


JSON object : View

Products Affected

redhat

  • icedtea
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor