Oracle already wins ‘crypto bug of the year’ with Java digital signature bypass

Java versions 15 to 18 contain a flaw in its ECDSA signature validation that makes it trivial for miscreants to digitally sign files and other data as if they were legit organizations. Cyber-criminals could therefore pass off cryptographically signed malicious downloads and bogus information as if it were real, and affected Java applications and services won’t know the difference.

Read full article on The Register

 


Date:

Categorie(s):