Back

HIGH

icedtea-web: unsigned code injection in a signed JAR file

Published Jul 31, 2019

Description

It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Jul 31, 2019
Updated Aug 4, 2024
Reserved Mar 27, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Jul 31, 2019
Bugzilla 1725928

ENISA EUVD

Assigner redhat
Published Jul 31, 2019
Updated Aug 4, 2024

GitHub

No data