CVE-2011-2514
EPSS 2.4%
描述
The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to trick victims into granting access to local files by modifying the content of the Java Web Start Security Warning dialog box to represent a different filename than the file for which access will be granted.
如何修補 CVE-2011-2514
要修補 CVE-2011-2514,請將受影響套件升級到下列已修補版本。
- Debian/icedtea-web—升級至 1.1-1 或更新版本
CVE-2011-2514 正在被利用嗎?
低 — EPSS 為 2.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1.1-1