Fedora 29 : icedtea-web (2019-efb92eed7a)

high Nessus Plugin ID 127536

Language:

Synopsis

The remote Fedora host is missing a security update.

Description

fixed CVEs 2019-10181, 2019-10182, 2019-10185

----

Updated to fres upstream release :

https://mail.openjdk.java.net/pipermail/distro-pkg-dev/2019-March/0413 20.html

New in release 1.8 (2019-03-12) :

- added support for javafx-desc and so allwong run of pure-javafx only applications

- --nosecurity enhanced for possibility to skip invalid signatures

- enhanced to allow resources to be read also from j2se/java element (OmegaT)

- PR3644 - java.lang.NoClassDefFoundError: Could not initialize class net.sourceforge.jnlp.runtime.JNLPRuntime$DeploymentConfi gurationHolder

- deployment.config now support generic url instead just file

- Added support for windows desktop shortcuts via https://github.com/DmitriiShamrikov/mslinks

- cache can now be operated by groups, list by -Xcacheids (details via -verbose, can filter by regex), Xclearcache now can clear only selected id. There is also gui to operate cache via id in itweb-settings now.

- desktop shortcut name get shortened to title or file if title is missing.

- shared native launchers

- scripted launchers rework: Windows bat launchers rewritten to be feature complete, Linux shell launchers made portable, build enhanced to produce platform independent image

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website.
Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected icedtea-web package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2019-efb92eed7a

Plugin Details

Severity: High

ID: 127536

File Name: fedora_2019-efb92eed7a.nasl

Version: 1.2

Type: local

Agent: unix

Published: 8/12/2019

Updated: 9/23/2019

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Vulnerability Information

CPE: cpe:/o:fedoraproject:fedora:29, p-cpe:/a:fedoraproject:fedora:icedtea-web

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 8/11/2019

Vulnerability Publication Date: 8/11/2019

Reference Information