IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9...
Moderate severity
Unreviewed
Published
May 3, 2022
to the GitHub Advisory Database
•
Updated Apr 11, 2025
Description
Published by the National Vulnerability Database
Feb 4, 2011
Published to the GitHub Advisory Database
May 3, 2022
Last updated
Apr 11, 2025
IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.
References