CVE-2011-0025 Information

Description

IcedTea 1.7 before 1.7.8 1.8 before 1.8.5 and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are \partially signed\ or (2) signed by multiple entities which allows remote attackers to trick users into executing code that appears to come from a trusted source.

Reference

http://blog.fuseyism.com/index.php/2011/02/01/security-icedtea6-178-185-195-released/ http://icedtea.classpath.org/hg/release/icedtea-web-1.0?cmd=changeset;node=3bd328e4b515 http://secunia.com/advisories/43135 http://security.gentoo.org/glsa/glsa-201406-32.xml http://www.debian.org/security/2011/dsa-2224 http://www.mandriva.com/security/advisories?name=MDVSA-2011:054 http://www.securityfocus.com/bid/46110 http://www.ubuntu.com/usn/USN-1055-1 https://exchange.xforce.ibmcloud.com/vulnerabilities/65151

Share on: