IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2011-02-04T19:00:00

Updated: 2024-08-06T21:43:13.999Z

Reserved: 2010-12-07T00:00:00

Link: CVE-2011-0025

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2011-02-04T20:00:02.447

Modified: 2024-11-21T01:23:08.837

Link: CVE-2011-0025

cve-icon Redhat

Severity : Important

Publid Date: 2011-02-01T00:00:00Z

Links: CVE-2011-0025 - Bugzilla