VulnerabilityModified
CVE-2019-10185
It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file.
HIGH 8.6EPSS 4.02%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.02%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.
- CVSS 3.1
- 8.6 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- EPSS
- 4.02% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- icedtea-web project/icedtea-web · debian/debian linux · opensuse/leap
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00045.htmlThird Party Advisory
- http://packetstormsecurity.com/files/154748/IcedTeaWeb-Validation-Bypass-Directory-Traversal-Code-Execution.htmlThird Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10185Issue Tracking, Third Party Advisory
- https://github.com/AdoptOpenJDK/IcedTea-Web/issues/327Third Party Advisory
- https://github.com/AdoptOpenJDK/IcedTea-Web/pull/344Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00008.htmlThird Party Advisory
- https://seclists.org/bugtraq/2019/Oct/5Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202107-51Patch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00045.htmlThird Party Advisory
- http://packetstormsecurity.com/files/154748/IcedTeaWeb-Validation-Bypass-Directory-Traversal-Code-Execution.htmlThird Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10185Issue Tracking, Third Party Advisory
- https://github.com/AdoptOpenJDK/IcedTea-Web/issues/327Third Party Advisory
- https://github.com/AdoptOpenJDK/IcedTea-Web/pull/344Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/09/msg00008.htmlThird Party Advisory
- https://seclists.org/bugtraq/2019/Oct/5Mailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202107-51Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.