Multiple vulnerabilities have been found in IcedTea, the worst of which could result in arbitrary code execution.
Package | dev-java/icedtea on all architectures |
---|---|
Affected versions | <= 3.21.0 |
Unaffected versions |
Package | dev-java/icedtea-bin on all architectures |
---|---|
Affected versions | <= 3.16.0-r2 |
Unaffected versions |
IcedTea’s aim is to provide OpenJDK in a form suitable for easy configuration, compilation and distribution with the primary goal of allowing inclusion in GNU/Linux distributions.
Multiple vulnerabilities have been discovered in IcedTea. Please review the CVE identifiers referenced below for details.
Please review the referenced CVE identifiers for details.
There is no known workaround at this time.
Gentoo has discontinued support for IcedTea. We recommend that users unmerge it:
# emerge --sync # emerge --ask --depclean "dev-java/icedtea" "dev-java/icedtea-bin"