Upstream information
Description
IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.NVD CVSS v2 Base Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entry: 667313 SUSE Security Advisories:- SUSE-SR:2011:003, published Tue, 08 Feb 2011 14:00:00 +0000
- openSUSE-SU-2011:0102-1, published Mon, 7 Feb 2011 14:08:14 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| openSUSE 11.2 openSUSE 11.3 |
| |
| openSUSE 11.2 openSUSE 11.3 |
|
