PT-2011-2022 · Oracle · Icedtea

CVE-2011-0025

·

Publicado

2011-02-04

·

Atualizado

2023-02-13

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IcedTea versions 1.7 through 1.7.7 IcedTea versions 1.8 through 1.8.4 IcedTea versions 1.9 through 1.9.4
Description The issue allows remote attackers to trick users into executing code that appears to come from a trusted source, due to improper verification of signatures for JAR files. This can occur with JAR files that are partially signed or signed by multiple entities.
Recommendations For IcedTea versions 1.7 through 1.7.7, update to version 1.7.8 or later. For IcedTea versions 1.8 through 1.8.4, update to version 1.8.5 or later. For IcedTea versions 1.9 through 1.9.4, update to version 1.9.5 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-0025
DSA-2224-1

Produtos afetados

Icedtea