CVE-2011-0025
Published Feb 4, 2011
Last updated 2 years ago
Overview
- Description
- IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.8
- Impact score
- 6.4
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-20
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:redhat:icedtea:1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4833BFF6-1B29-4455-BA90-A11DE1F6D008" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD18B06E-F419-4ADE-B6E5-DC364A9FF6CD" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.7.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ED3970CE-8C3C-4F30-8927-1E5A6CD626E8" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.7.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E225339C-A5A8-4D56-A5EC-09814C83E0E2" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.7.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ADC26C27-DAD1-4DA9-A1DE-E3D5060C3EB7" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.7.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "557CEA5C-2B78-4BC2-ABA2-E2272D3765A2" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.7.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "39BB9DB4-AE61-4B74-B0AB-2363A5F4A9F0" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.7.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0FAC1F98-711A-4A9D-B81A-5B8180E4A006" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "68D8D8B4-8E82-4D08-9D39-2D94418D06E4" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.8.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C3AD9684-D2D7-496B-B77A-2798244CB112" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.8.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C6D37313-09D9-4726-B083-1FD83A602DE3" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.8.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CCFB7FF0-B2D7-43F2-86ED-0DC4966373E8" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.8.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "880A1C3A-9210-4263-9F16-F78C36B7DD9C" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3303605E-F164-4B9F-90E5-55E47C1C568B" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.9.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7C448596-505E-451B-8BC5-73FCB2D11DE6" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.9.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "39ECCC84-CA5A-44F7-B303-25BED16073B8" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.9.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4D454FC4-329C-4C70-BF31-D3F8B6CF85E6" }, { "criteria": "cpe:2.3:a:redhat:icedtea:1.9.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9D112A9B-C489-49FA-B446-54AEF1F515F1" } ], "operator": "OR" } ] } ]