IcedTea-Web prior to 1.5.3 and 1.6.x prior to 1.6.1 does not properly determine the origin of unsigned applets, which allows remote malicious users to bypass the approval process or trick users into approving applet execution via a crafted web page.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
fedoraproject fedora 21 |
||
fedoraproject fedora 22 |
||
redhat enterprise linux server 6.0 |
||
redhat enterprise linux desktop 6.0 |
||
redhat enterprise linux hpc node 6 |
||
redhat enterprise linux workstation 6.0 |
||
opensuse opensuse 13.2 |
||
opensuse opensuse 13.1 |
||
redhat icedtea |
||
redhat icedtea 1.6 |