IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2011-02-04T19:00:00

Updated: 2017-08-16T14:57:01

Reserved: 2010-12-07T00:00:00


Link: CVE-2011-0025

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2011-02-04T20:00:02.447

Modified: 2023-02-13T00:15:51.857


Link: CVE-2011-0025

JSON object: View

cve-icon Redhat Information

No data.

CWE