IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2015-10-09 07:59
Updated : 2018-10-30 09:27
NVD link : CVE-2015-5234
Mitre link : CVE-2015-5234
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
redhat
- enterprise_linux_desktop
- enterprise_linux_hpc_node
- icedtea
- enterprise_linux_workstation
- enterprise_linux_server
fedoraproject
- fedora
opensuse
- opensuse