6.8
CVSSv2

CVE-2015-5234

Published: 09/10/2015 Updated: 30/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

IcedTea-Web prior to 1.5.3 and 1.6.x prior to 1.6.1 does not properly sanitize applet URLs, which allows remote malicious users to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise linux workstation 6.0

redhat enterprise linux desktop 6.0

redhat enterprise linux hpc node 6.0

redhat enterprise linux server 6.0

opensuse opensuse 13.1

opensuse opensuse 13.2

redhat icedtea

redhat icedtea 1.6

fedoraproject fedora 22

fedoraproject fedora 21

Vendor Advisories

Debian Bug report logs - #798467 icedtea-web: CVE-2015-5234 CVE-2015-5235 Package: icedtea-web; Maintainer for icedtea-web is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Wed, 9 Sep 2015 17:45:06 UTC Severity: grave Tags: security Fou ...
Several security issues were fixed in IcedTea Web ...