IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
History
No history.
Information
Published : 2015-10-09 14:59
Updated : 2024-02-04 18:53
NVD link : CVE-2015-5234
Mitre link : CVE-2015-5234
CVE.ORG link : CVE-2015-5234
JSON object : View
Products Affected
redhat
- enterprise_linux_hpc_node
- icedtea
- enterprise_linux_workstation
- enterprise_linux_server
- enterprise_linux_desktop
opensuse
- opensuse
fedoraproject
- fedora
CWE
CWE-20
Improper Input Validation