MEDIUM
icedtea-web: applet origin spoofing
Published Oct 9, 2015
4.3
MEDIUMCVSS 2.0
EPSS 3.02%
Description
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.
Affected products
No data.
Configuration 1
OR
- 21
- 22
Configuration 2
OR
- 6.0
- 6
- 6.0
- 6.0
No data.
Red Hat Enterprise Linux 6
icedtea-web-0:1.6.2-1.el6
Fixed · RHSA-2016:0778
Red Hat Enterprise Linux 7
icedtea-web-0:1.6.1-4.el7
Fixed · RHBA-2015:2457
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | icedtea-web-0:1.6.2-1.el6 | Fixed | RHSA-2016:0778 |
| Red Hat Enterprise Linux 7 | icedtea-web-0:1.6.1-4.el7 | Fixed | RHBA-2015:2457 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (13)
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167120.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167130.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00019.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2015-September/033546.html mailing-listx_refsource_MLISTPatch
- http://rhn.redhat.com/errata/RHSA-2016-0778.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html x_refsource_CONFIRM
- http://www.securitytracker.com/id/1033780 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/USN-2817-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2015-5235 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1233697 x_refsource_CONFIRMIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2015-5231 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-5235
- https://www.cve.org/CVERecord?id=CVE-2015-5235
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 9, 2015
Updated Aug 6, 2024
Reserved Jul 1, 2015
Link CVE-2015-5235
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2015-5231 Assigner redhat
Published Oct 9, 2015
Updated Aug 6, 2024
Exploited since n/a
Link EUVD-2015-5231