First published: Thu Oct 31 2019(Updated: )
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/openjdk-6 | ||
redhat IcedTea6 | <1.7.4 | |
Red Hat IcedTea6 | <1.7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-2548 is considered to have a moderate severity level due to the potential for data exposure and unauthorized file manipulation.
To fix CVE-2010-2548, update to IcedTea6 version 1.7.4 or later.
CVE-2010-2548 primarily affects systems using IcedTea6 versions prior to 1.7.4 including those on Debian and Red Hat.
Applications using IcedTea6 vulnerable to CVE-2010-2548 may allow unsigned apps to read and write sensitive files, leading to potential data breaches.
While CVE-2010-2548 is an older vulnerability, any systems running affected versions remain at risk if not updated.