It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N)
- CVSS 3.0 Base Score: 8.2
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | No Centos packages or updates have been released to address this issue | Aug 28, 2019 | Jul 31, 2019 |
| Debian | — | Upgrade icedtea-web | Sep 11, 2019 | Jul 31, 2019 |
| Gentoo Linux | — | Upgrade dev-java/icedtea-web. | Jul 26, 2021 | Jul 31, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade icedtea-web | Sep 12, 2019 | Jul 31, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade icedtea-web | Aug 31, 2020 | Jul 31, 2019 |
| Oracle_linux | — | Upgrade icedtea-webUpgrade icedtea-web-develUpgrade icedtea-web-javadoc | Jul 21, 2020 | Jul 31, 2019 |
| Redhat_linux | — | No solution existsUpgrade icedtea-webUpgrade icedtea-web-javadocUpgrade icedtea-web-develUpgrade icedtea-web-debuginfo | Aug 1, 2019 | Jul 31, 2019 |
| Suse | — | Upgrade icedtea-webUpgrade icedtea-web-javadoc | Aug 16, 2019 | Jul 31, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 31, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub