IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://security-tracker.debian.org/tracker/CVE-2010-2783 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-2783 | issue tracking vendor advisory |
http://security.gentoo.org/glsa/glsa-201406-32.xml | third party advisory |
http://blog.fuseyism.com/index.php/2010/07/28/icedtea6-174-released/ | third party advisory patch |