CVE-2013-4578 PUBLISHED

Reported by redhat · Published December 29, 2017

jarsigner in OpenJDK and Oracle Java SE before 7u51 allows remote attackers to bypass a code-signing protection mechanism and inject unsigned bytecode into a signed JAR file by leveraging improper file validation.

Affected Products

VendorProductVersions
n/an/an/a
n/an/an/a
chainguardopenjdk-17-openj90
chainguardopenjdk-21-openj90
chainguardopenjdk-11-openj90
chainguardopenjdk-8-openj90

Timeline

References

Open in Interactive Console →