From 8a7cd2a4017c4e3110f9d9668fc8a439110bf2a1 Mon Sep 17 00:00:00 2001 From: Weijun Wang Date: Fri, 13 Sep 2013 15:37:43 +0800 Subject: [PATCH] 8023672: Enhance jar file validation Also reviewed by Chris Ries and Alexander Fomin Reviewed-by: mullan, sherman --- jdk/src/share/classes/java/util/jar/JarVerifier.java | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/jdk/src/share/classes/java/util/jar/JarVerifier.java b/jdk/src/share/classes/java/util/jar/JarVerifier.java index 30459e54324..2b6b1451a5a 100644 --- a/jdk/src/share/classes/java/util/jar/JarVerifier.java +++ b/jdk/src/share/classes/java/util/jar/JarVerifier.java @@ -179,7 +179,9 @@ class JarVerifier { name = name.substring(1); // only set the jev object for entries that have a signature - if (sigFileSigners.get(name) != null) { + // (either verified or not) + if (sigFileSigners.get(name) != null || + verifiedSigners.get(name) != null) { mev.setEntry(name, je); return; }