First published: Thu Jul 15 2021(Updated: )
A flaw was found in the way the Library component of OpenJDK handled JAR files containing multiple MANIFEST.MF files. Such JAR files could cause signature verification process to return an incorrect result, possibly allowing tampering with signed JAR files. After the fix, all JAR files with multiple MANIFEST.MF files are treated as unsigned.
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJDK |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1982879 is classified as high due to the potential for tampering with signed JAR files.
To fix REDHAT-BUG-1982879, you should update to the latest version of OpenJDK where the flaw has been addressed.
REDHAT-BUG-1982879 affects systems running OpenJDK that utilize JAR files with multiple MANIFEST.MF files.
REDHAT-BUG-1982879 could potentially allow malicious actors to tamper with the contents of signed JAR files, undermining application integrity.
There is no known workaround for REDHAT-BUG-1982879, so it is recommended to apply the available updates as soon as possible.