First published: Mon Feb 14 2011(Updated: )
The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of "an inappropriate security descriptor."
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat IcedTea-Web | =1.0 | |
Red Hat IcedTea-Web | =1.0-pre | |
Red Hat IcedTea-Web | =1.0.1-pre | |
Java Development Kit (JDK) | =1.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0706 is considered a medium severity vulnerability due to its potential to allow remote attackers to gain privileges.
To fix CVE-2011-0706, upgrade to IcedTea-Web version 1.0.1 or later if you are using OpenJDK Runtime Environment 1.6.0.
CVE-2011-0706 affects IcedTea-Web versions before 1.0.1 and OpenJDK version 1.6.0.
CVE-2011-0706 is a privilege escalation vulnerability related to the JNLPClassLoader class in IcedTea-Web.
Yes, CVE-2011-0706 can be exploited remotely by attackers to gain elevated privileges.