IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which allows remote attackers to obtain sensitive information including (1) user.name, (2) user.home, and (3) java.home system properties, and other sensitive information such as installation directories.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2010-12-08T19:00:00

Updated: 2014-10-02T13:57:01

Reserved: 2010-10-08T00:00:00


Link: CVE-2010-3860

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2010-12-08T20:00:01.370

Modified: 2014-10-04T04:29:42.433


Link: CVE-2010-3860

JSON object: View

cve-icon Redhat Information

No data.

CWE