High severity8.6NVD Advisory· Published Jul 31, 2019· Updated Jun 17, 2026
CVE-2019-10185
CVE-2019-10185
Description
It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13cpe:2.3:a:icedtea-web_project:icedtea-web:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:icedtea-web_project:icedtea-web:*:*:*:*:*:*:*:*range: <=1.7.2
- cpe:2.3:a:icedtea-web_project:icedtea-web:1.8.2:*:*:*:*:*:*:*
- Range: <=1.7.2, <=1.8.2
- osv-coords7 versionspkg:rpm/opensuse/icedtea-web&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/icedtea-web&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/icedtea-web&distro=openSUSE%20Tumbleweedpkg:rpm/suse/icedtea-web&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3pkg:rpm/suse/icedtea-web&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP4pkg:rpm/suse/icedtea-web&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/icedtea-web&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP3
< 1.7.2-lp150.2.3.1+ 6 more
- (no CPE)range: < 1.7.2-lp150.2.3.1
- (no CPE)range: < 1.7.2-150100.7.3.1
- (no CPE)range: < 1.8.6-1.3
- (no CPE)range: < 1.7.2-150100.7.3.1
- (no CPE)range: < 1.7.2-150100.7.3.1
- (no CPE)range: < 1.7.2-3.3.1
- (no CPE)range: < 1.7.2-150100.7.3.1
- IcedTea/icedtea-webv5Range: affects up to and including 1.7.2 and 1.8.2
Patches
Vulnerability mechanics
References
8- github.com/AdoptOpenJDK/IcedTea-Web/pull/344nvdPatchThird Party Advisory
- security.gentoo.org/glsa/202107-51nvdPatchThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-08/msg00045.htmlnvdThird Party Advisory
- packetstormsecurity.com/files/154748/IcedTeaWeb-Validation-Bypass-Directory-Traversal-Code-Execution.htmlnvdThird Party AdvisoryVDB Entry
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- github.com/AdoptOpenJDK/IcedTea-Web/issues/327nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2019/09/msg00008.htmlnvdThird Party Advisory
- seclists.org/bugtraq/2019/Oct/5nvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.