IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2224-1 | openjdk-6 security update |
EUVD |
EUVD-2011-0051 | IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source. |
Ubuntu USN |
USN-1055-1 | OpenJDK vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 28 May 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Thu, 22 May 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T21:43:13.999Z
Reserved: 2010-12-07T00:00:00
Link: CVE-2011-0025
No data.
Status : Deferred
Published: 2011-02-04T20:00:02.447
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-0025
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN