PublicDateAtUSN: 2015-10-09 Candidate: CVE-2015-5234 PublicDate: 2015-10-09 14:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5234 https://ubuntu.com/security/notices/USN-2817-1 Description: IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks. Ubuntu-Description: Notes: mdeslaur> extended applets security was introduced in icedtea-web 1.4 Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=798467 https://bugzilla.redhat.com/show_bug.cgi?id=1233667 Priority: medium Discovered-by: Assigned-to: sbeattie CVSS: Patches_icedtea-web: upstream: http://icedtea.classpath.org/hg/icedtea-web/rev/53500e3de1bc upstream: http://icedtea.classpath.org/hg/icedtea-web/rev/c9befa549f63 upstream: http://icedtea.classpath.org/hg/icedtea-web/rev/5ddfe3e389ab upstream: http://icedtea.classpath.org/hg/icedtea-web/rev/1a1cbf3b1123 upstream_icedtea-web: released (1.5.3) precise_icedtea-web: not-affected (code not present) trusty_icedtea-web: released (1.5.3-0ubuntu0.14.04.1) trusty/esm_icedtea-web: DNE (trusty was released [1.5.3-0ubuntu0.14.04.1]) vivid_icedtea-web: released (1.5.3-0ubuntu0.15.04.1) wily_icedtea-web: released (1.5.3-0ubuntu0.15.10.1) devel_icedtea-web: released (1.5.3-0ubuntu1)