SUSE-SU-2022:1259-1
Dashboard / Vulnerabilities / SUSE-SU-2022:1259-1
SUSE-SU-2022:1259-1
Summary: Security update for icedtea-web
Details: This update for icedtea-web fixes the following issues: - CVE-2019-10181: Fixed an issue where an attacker could inject unsigned code in a signed JAR file (bsc#1142835). - CVE-2019-10182: Fixed a path traversal issue where an attacker could upload arbritrary files by tricking a victim into running a specially crafted application(bsc#1142825). - CVE-2019-10185: Fixed an issue where an attacker could write files to arbitrary locations during JAR auto-extraction (bsc#1142832).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20221259-1/, https://bugzilla.suse.com/1142825, https://bugzilla.suse.com/1142832, https://bugzilla.suse.com/1142835, https://www.suse.com/security/cve/CVE-2019-10181, https://www.suse.com/security/cve/CVE-2019-10182, https://www.suse.com/security/cve/CVE-2019-10185
Affected packages
Package
Name: icedtea-web
Purl: pkg:rpm/suse/icedtea-web&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
