IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Information
Published : 2015-10-09 07:59
Updated : 2018-10-30 09:27
NVD link : CVE-2015-5235
Mitre link : CVE-2015-5235
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
redhat
- enterprise_linux_desktop
- enterprise_linux_hpc_node
- icedtea
- enterprise_linux_workstation
- enterprise_linux_server
fedoraproject
- fedora
opensuse
- opensuse