6.8
CVSSv2

CVE-2011-0025

Published: 04/02/2011 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

IcedTea 1.7 prior to 1.7.8, 1.8 prior to 1.8.5, and 1.9 prior to 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote malicious users to trick users into executing code that appears to come from a trusted source.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat icedtea 1.9.3

redhat icedtea 1.8.1

redhat icedtea 1.9.4

redhat icedtea 1.7.7

redhat icedtea 1.7.2

redhat icedtea 1.8.3

redhat icedtea 1.8

redhat icedtea 1.7.3

redhat icedtea 1.7.5

redhat icedtea 1.8.4

redhat icedtea 1.7.4

redhat icedtea 1.7.6

redhat icedtea 1.8.2

redhat icedtea 1.7.1

redhat icedtea 1.9.2

redhat icedtea 1.9

redhat icedtea 1.9.1

redhat icedtea 1.7

Vendor Advisories

It was discovered that IcedTea for Java did not properly verify signatures when handling multiply signed or partially signed JAR files, allowing an attacker to cause code to execute that appeared to come from a verified source (CVE-2011-0025) ...
Several security vulnerabilities were discovered in OpenJDK, an implementation of the Java platform CVE-2010-4351 The JNLP SecurityManager returns from the checkPermission method instead of throwing an exception in certain circumstances, which might allow context-dependent attackers to bypass the intended security policy by creati ...