Bug 663680 (CVE-2010-4351) - CVE-2010-4351 IcedTea jnlp security manager bypass
Summary: CVE-2010-4351 IcedTea jnlp security manager bypass
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2010-4351
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
: 664841 (view as bug list)
Depends On: 668487
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-12-16 15:50 UTC by Marc Schoenefeld
Modified: 2023-05-12 22:34 UTC (History)
7 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-07-01 13:04:31 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Bugzilla 664841 1 None None None 2022-05-16 08:48:00 UTC
Red Hat Product Errata RHSA-2011:0176 0 normal SHIPPED_LIVE Moderate: java-1.6.0-openjdk security update 2011-01-25 16:20:12 UTC

Internal Links: 664841

Comment 8 Marc Schoenefeld 2011-01-18 15:25:12 UTC
It was discovered that the JNLPSecurityManager in certain cases failed to properly implement the security policy, and did not throw an exception to prevent completion of a possibly unsafe or sensitive operation and simply returned from the checkPermission method. 

Any service relying on the SecurityManager.checkPermission() method to throw an exception then incorrectly assumed that the permission was granted.

The issue was independently reported by Omair Majid for JNLP applications, and for applets by a reporter cooperating with the TippingPoint Zero Day Initiave. 

Reference: 
http://blog.fuseyism.com/index.php/2011/01/18/security-icedtea6-177-184-194-released/

Patch Information: 

http://icedtea.classpath.org/hg/release/icedtea6-1.7/rev/6f7d633c355a http://icedtea.classpath.org/hg/release/icedtea6-1.8/rev/aa77afad613c http://icedtea.classpath.org/hg/release/icedtea6-1.9/rev/7ec6c82e69ee

Acknowledgements:

Red Hat would like to thank the TippingPoint Zero Day Initiative project for reporting this issue. The original issue reporter wishes to stay anonymous.

Comment 9 errata-xmlrpc 2011-01-25 16:20:18 UTC
This issue has been addressed in following products:

  Red Hat Enterprise Linux 5

Via RHSA-2011:0176 https://rhn.redhat.com/errata/RHSA-2011-0176.html

Comment 10 Tomas Hoger 2011-06-08 15:32:35 UTC
*** Bug 664841 has been marked as a duplicate of this bug. ***


Note You need to log in before you can comment on or make changes to this bug.