CVE-2011-0706: High severity red hat icedtea-web vulnerability
The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of "an inappropriate security descriptor."
Other sources
The JNLPClassLoader implementation incorrectly assigns ALLPERMISSIONS to untrusted code in multiple signer scenarios. An attacker could misuse this to elevate privileges.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0706?
CVE-2011-0706 is considered a medium severity vulnerability due to its potential to allow remote attackers to gain privileges.
How do I fix CVE-2011-0706?
To fix CVE-2011-0706, upgrade to IcedTea-Web version 1.0.1 or later if you are using OpenJDK Runtime Environment 1.6.0.
Which software versions are affected by CVE-2011-0706?
CVE-2011-0706 affects IcedTea-Web versions before 1.0.1 and OpenJDK version 1.6.0.
What type of vulnerability is CVE-2011-0706?
CVE-2011-0706 is a privilege escalation vulnerability related to the JNLPClassLoader class in IcedTea-Web.
Can CVE-2011-0706 be exploited remotely?
Yes, CVE-2011-0706 can be exploited remotely by attackers to gain elevated privileges.