First published: Fri Feb 04 2011(Updated: )
IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Icedtea | =1.9.3 | |
Redhat Icedtea | =1.8.1 | |
Redhat Icedtea | =1.9.4 | |
Redhat Icedtea | =1.7.7 | |
Redhat Icedtea | =1.7.2 | |
Redhat Icedtea | =1.8.3 | |
Redhat Icedtea | =1.8 | |
Redhat Icedtea | =1.7.3 | |
Redhat Icedtea | =1.7.5 | |
Redhat Icedtea | =1.8.4 | |
Redhat Icedtea | =1.7.4 | |
Redhat Icedtea | =1.7.6 | |
Redhat Icedtea | =1.8.2 | |
Redhat Icedtea | =1.7.1 | |
Redhat Icedtea | =1.9.2 | |
Redhat Icedtea | =1.9 | |
Redhat Icedtea | =1.9.1 | |
Redhat Icedtea | =1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.