CVE-2019-10185
Last modified
CVE-2019-10185 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. EPSS estimates a 4.02% chance of exploitation in the next 30 days.
Description
It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Icedtea-Web Project | Icedtea-Web | <= 1.7.2 |
| Icedtea-Web Project | Icedtea-Web | 1.8.2 |
| Debian | Debian Linux | 8.0 |
| Opensuse | Leap | 15.0 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00045.htmlThird Party Advisory
- http://packetstormsecurity.com/files/154748/IcedTeaWeb-Validation-Bypass-Directory-Traversal-Code-Execution.htmlThird Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10185Issue Tracking, Third Party Advisory
- https://github.com/AdoptOpenJDK/IcedTea-Web/issues/327Third Party Advisory
- https://github.com/AdoptOpenJDK/IcedTea-Web/pull/344Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00008.htmlThird Party Advisory
- https://seclists.org/bugtraq/2019/Oct/5Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202107-51Patch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00045.htmlThird Party Advisory
- http://packetstormsecurity.com/files/154748/IcedTeaWeb-Validation-Bypass-Directory-Traversal-Code-Execution.htmlThird Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10185Issue Tracking, Third Party Advisory
- https://github.com/AdoptOpenJDK/IcedTea-Web/issues/327Third Party Advisory
- https://github.com/AdoptOpenJDK/IcedTea-Web/pull/344Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00008.htmlThird Party Advisory
- https://seclists.org/bugtraq/2019/Oct/5Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202107-51Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-10185?
How severe is CVE-2019-10185?
How do I fix CVE-2019-10185?
Are you affected by CVE-2019-10185?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
