IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2010-2548 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2548 | issue tracking vendor advisory |
http://blog.fuseyism.com/index.php/2010/07/28/icedtea6-174-released/ | third party advisory patch |