IcedTea-arbitrary Web code injection vulnerability (CVE-2015-5234)
IcedTea-arbitrary Web code injection vulnerability (CVE-2015-5234)
Release date:
Updated on:
Affected Systems:
IcedTea-Web <1.5.3
IcedTea-Web 1.6.x-1.6.1
Description:
CVE (CAN) ID: CVE-2015-5234
IcedTea-Web is a free Java Web browser plug-in.
In versions earlier than IcedTea-Web 1.5.3 and 1.6.x-1.6.1, the URL of a small application is not properly filtered. This vulnerability can be exploited by remote attackers to inject small applications into a webpage. appletTrustSettings configuration file and execute.
<* Source: Andrea Palazzo
*>
Suggestion:
Vendor patch:
IcedTea
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1233667
This article permanently updates the link address: