[Forgot Password]
Login  Register Subscribe

23631

 
 

126951

 
 

99602

 
 

909

 
 

80167

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2013-4578

Date: (C)2018-01-02   (M)2018-01-05 


jarsigner in OpenJDK and Oracle Java SE before 7u51 allows remote attackers to bypass a code-signing protection mechanism and inject unsigned bytecode into a signed JAR file by leveraging improper file validation.

CVSS Score: Access Vector:
Exploit Score: Access Complexity:
Impact Score: Authentication:
 Confidentiality:
 Integrity:
 Availability:





Reference:
RHSA-2014:0414
http://www.openwall.com/lists/oss-security/2015/02/08/6
http://www.openwall.com/lists/oss-security/2015/02/09/9
http://hg.openjdk.java.net/jdk7u/jdk7u/jdk/rev/d5f36e1c927e
https://bugzilla.redhat.com/show_bug.cgi?id=1031471

© 2013 SecPod Technologies