CVE-2011-2513
EPSS 2.5%
描述
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to obtain the username and full path of the home and cache directories by accessing properties of the ClassLoader.
如何修補 CVE-2011-2513
要修補 CVE-2011-2513,請將受影響套件升級到下列已修補版本。
- Debian/icedtea-web—升級至 1.1.2-1 或更新版本
CVE-2011-2513 正在被利用嗎?
低 — EPSS 為 2.5%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1.1.2-1