REDHAT-BUG-1982879: Medium severity openjdk vulnerability
A flaw was found in the way the Library component of OpenJDK handled JAR files containing multiple MANIFEST.MF files. Such JAR files could cause signature verification process to return an incorrect result, possibly allowing tampering with signed JAR files. After the fix, all JAR files with multiple MANIFEST.MF files are treated as unsigned.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1982879?
The severity of REDHAT-BUG-1982879 is classified as high due to the potential for tampering with signed JAR files.
How do I fix REDHAT-BUG-1982879?
To fix REDHAT-BUG-1982879, you should update to the latest version of OpenJDK where the flaw has been addressed.
What systems are affected by REDHAT-BUG-1982879?
REDHAT-BUG-1982879 affects systems running OpenJDK that utilize JAR files with multiple MANIFEST.MF files.
What impact does REDHAT-BUG-1982879 have on application security?
REDHAT-BUG-1982879 could potentially allow malicious actors to tamper with the contents of signed JAR files, undermining application integrity.
Is there a workaround for REDHAT-BUG-1982879?
There is no known workaround for REDHAT-BUG-1982879, so it is recommended to apply the available updates as soon as possible.