Debian Package Tracker
Register | Log in
Subscribe

icedtea-web

Implementation of the Java Network Launching Protocol (JNLP)

Choose email to subscribe with

general
  • source: icedtea-web (main)
  • version: 1.8.8-1
  • maintainer: Debian Java Maintainers (archive) (DMD)
  • uploaders: Matthias Klose [DMD]
  • arch: all
  • std-ver: 4.6.0.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.6.2-3.1+deb9u1
  • oldstable: 1.7.2-2
  • stable: 1.8.4-1
  • testing: 1.8.8-1
  • unstable: 1.8.8-1
versioned links
  • 1.6.2-3.1+deb9u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.7.2-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.8.4-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.8.8-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • icedtea-netx (11 bugs: 0, 10, 1, 0)
action needed
Depends on packages which need a new maintainer normal
The packages that icedtea-web depends on which need a new maintainer are:
  • dh-exec (#851746)
    • Build-Depends: dh-exec
Created: 2019-11-22 Last update: 2022-05-16 19:14
AppStream hints: 1 warning normal
AppStream found metadata issues for packages:
  • icedtea-netx: 1 warning
You should get rid of them to provide more metadata about this software.
Created: 2020-06-01 Last update: 2020-06-01 01:13
3 low-priority security issues in buster low

There are 3 open security issues in buster.

3 issues left for the package maintainer to handle:
  • CVE-2019-10181: (needs triaging) It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.
  • CVE-2019-10182: (needs triaging) It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.
  • CVE-2019-10185: (needs triaging) It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.

You can find information about how to handle these issues in the security team's documentation.

Created: 2021-02-19 Last update: 2022-05-10 08:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.1 instead of 4.6.0.1).
Created: 2022-05-11 Last update: 2022-05-11 23:25
news
[rss feed]
  • [2022-05-10] icedtea-web 1.8.8-1 MIGRATED to testing (Debian testing watch)
  • [2022-05-05] Accepted icedtea-web 1.8.8-1 (source) into unstable (Emmanuel Bourg)
  • [2020-06-13] icedtea-web 1.8.4-1 MIGRATED to testing (Debian testing watch)
  • [2020-06-07] Accepted icedtea-web 1.8.4-1 (source) into unstable (Emmanuel Bourg)
  • [2019-09-17] icedtea-web 1.8.3-2 MIGRATED to testing (Debian testing watch)
  • [2019-09-11] Accepted icedtea-web 1.8.3-2 (source) into unstable (Emmanuel Bourg)
  • [2019-09-09] Accepted icedtea-web 1.5.3-1+deb8u1 (source amd64 all) into oldoldstable (Markus Koschany)
  • [2019-08-15] icedtea-web 1.8.3-1 MIGRATED to testing (Debian testing watch)
  • [2019-08-09] Accepted icedtea-web 1.8.3-1 (source) into unstable (Emmanuel Bourg)
  • [2019-07-27] icedtea-web 1.8.2-2 MIGRATED to testing (Debian testing watch)
  • [2019-07-22] Accepted icedtea-web 1.8.2-2 (source) into unstable (Emmanuel Bourg)
  • [2019-07-18] Accepted icedtea-web 1.8.2-1 (source) into unstable (Emmanuel Bourg)
  • [2019-03-23] icedtea-web 1.7.2-2 MIGRATED to testing (Debian testing watch)
  • [2019-03-18] Accepted icedtea-web 1.7.2-2 (source) into unstable (Emmanuel Bourg)
  • [2019-03-15] Accepted icedtea-web 1.7.2-1 (source) into unstable (Emmanuel Bourg)
  • [2019-02-09] Accepted icedtea-web 1.6.2-3.1+deb9u1 (source all amd64) into proposed-updates->stable-new, proposed-updates (Moritz Mühlenhoff)
  • [2018-10-24] Accepted icedtea-web 1.7.1-1 (source) into unstable (Emmanuel Bourg)
  • [2017-01-25] icedtea-web 1.6.2-3.1 MIGRATED to testing (Debian testing watch)
  • [2017-01-14] Accepted icedtea-web 1.6.2-3.1 (source) into unstable (Adrian Bunk)
  • [2016-08-05] Accepted icedtea-web 1.4-3~deb7u3 (source all amd64) into oldstable (Emilio Pozuelo Monfort)
  • [2016-05-25] Accepted icedtea-web 1.5.3-1 (source amd64 all) into proposed-updates->stable-new, proposed-updates (Moritz Mühlenhoff)
  • [2016-05-04] Accepted icedtea-web 1.4-3~deb7u2 (source amd64 all) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Salvatore Bonaccorso)
  • [2016-05-04] Accepted icedtea-web 1.4-3~deb7u1 (source amd64 all) into oldstable-proposed-updates->oldstable-new, oldstable-proposed-updates (Moritz Mühlenhoff)
  • [2016-04-22] icedtea-web 1.6.2-3 MIGRATED to testing (Debian testing watch)
  • [2016-04-16] Accepted icedtea-web 1.6.2-3 (source amd64 all) into unstable (Matthias Klose)
  • [2016-02-07] Accepted icedtea-web 1.6.2-2 (source amd64 all) into unstable (Matthias Klose)
  • [2016-02-06] Accepted icedtea-web 1.6.2-1 (source amd64 all) into unstable (Matthias Klose)
  • [2016-02-03] icedtea-web 1.6.1-4 MIGRATED to testing (Debian testing watch)
  • [2016-01-28] Accepted icedtea-web 1.6.1-4 (source amd64 all) into unstable (Matthias Klose)
  • [2016-01-27] Accepted icedtea-web 1.6.1-3 (source amd64 all) into unstable (Matthias Klose)
  • 1
  • 2
bugs [bug history graph]
  • all: 12
  • RC: 0
  • I&N: 11
  • M&W: 1
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, clang, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.8.8-1
  • 72 bugs (1 patch)

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing