Bug 663680 - (CVE-2010-4351) CVE-2010-4351 IcedTea jnlp security manager bypass
CVE-2010-4351 IcedTea jnlp security manager bypass
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
Unspecified Unspecified
high Severity high
: ---
: ---
Assigned To: Red Hat Product Security
: Security
: 664841 (view as bug list)
Depends On: 668487
  Show dependency treegraph
Reported: 2010-12-16 10:50 EST by Marc Schoenefeld
Modified: 2012-07-13 13:27 EDT (History)
7 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2011-07-01 09:04:31 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Comment 8 Marc Schoenefeld 2011-01-18 10:25:12 EST
It was discovered that the JNLPSecurityManager in certain cases failed to properly implement the security policy, and did not throw an exception to prevent completion of a possibly unsafe or sensitive operation and simply returned from the checkPermission method. 

Any service relying on the SecurityManager.checkPermission() method to throw an exception then incorrectly assumed that the permission was granted.

The issue was independently reported by Omair Majid for JNLP applications, and for applets by a reporter cooperating with the TippingPoint Zero Day Initiave. 


Patch Information: 

http://icedtea.classpath.org/hg/release/icedtea6-1.7/rev/6f7d633c355a http://icedtea.classpath.org/hg/release/icedtea6-1.8/rev/aa77afad613c http://icedtea.classpath.org/hg/release/icedtea6-1.9/rev/7ec6c82e69ee


Red Hat would like to thank the TippingPoint Zero Day Initiative project for reporting this issue. The original issue reporter wishes to stay anonymous.
Comment 9 errata-xmlrpc 2011-01-25 11:20:18 EST
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2011:0176 https://rhn.redhat.com/errata/RHSA-2011-0176.html
Comment 10 Tomas Hoger 2011-06-08 11:32:35 EDT
*** Bug 664841 has been marked as a duplicate of this bug. ***

Note You need to log in before you can comment on or make changes to this bug.