IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-java/icedtea-bin. | Oct 30, 2017 | Feb 4, 2011 |
| Suse | — | Upgrade java-1_6_0-openjdk-pluginUpgrade java-1_6_0-openjdk-develUpgrade java-1_6_0-openjdkUpgrade java-1_6_0-openjdk-srcUpgrade java-1_6_0-openjdk-demoUpgrade java-1_6_0-openjdk-javadoc | Feb 17, 2015 | Feb 4, 2011 |
| Ubuntu | — | Upgrade icedtea6-plugin | Nov 8, 2024 | Feb 4, 2011 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub