CVE-2011-0706

Published: 18 February 2011

The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of "an inappropriate security descriptor."

Priority

Medium

Status

Package Release Status
openjdk-6
Launchpad, Ubuntu, Debian
Upstream
Released (IcedTea 1.9.7)
openjdk-6b18
Launchpad, Ubuntu, Debian
Upstream
Released (IcedTea 1.8.7)