CVE-2015-5234
published 2015-10-09CVE-2015-5234: IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the…
PriorityP429medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.13%
79.8th percentile
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | icedtea-web | < icedtea-web 1.6.1-1 (bookworm) | icedtea-web 1.6.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | icedtea | <= 1.5.2 | — |
| redhat | icedtea | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
IcedTea Web vulnerabilities
vendor_ubuntu·2015-11-24·CVSS 6.8
CVE-2015-5234 [MEDIUM] IcedTea Web vulnerabilities
Title: IcedTea Web vulnerabilities
Summary: Several security issues were fixed in IcedTea Web.
It was discovered that IcedTea Web incorrectly handled applet URLs. A
remote attacker could possibly use this issue to inject applets into the
.appletTrustSettings configuration file and bypass user approval.
(CVE-2015-5234)
Andrea Palazzo discovered that IcedTea Web incorrectly determined the
origin of unsigned applets. A remote attacker could possibly use this issue
to bypass user approval, or to trick the user into approving applet
execution. (CVE-2015-5235)
Instructions: After a standard system update you need to restart your browser to make
all the necessary changes.
Red Hat
icedtea-web: unexpected permanent authorization of unsigned applets
vendor_redhat·2015-09-02·CVSS 6.8
CVE-2015-5234 [MEDIUM] CWE-138 icedtea-web: unexpected permanent authorization of unsigned applets
icedtea-web: unexpected permanent authorization of unsigned applets
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.
It was discovered that IcedTea-Web did not properly sanitize applet URLs when storing applet trust settings. A malicious web page could use this flaw to inject trust-settings configuration, and cause applets to be executed without user approval.
Debian
CVE-2015-5234: icedtea-web - IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize apple...
vendor_debian·2015·CVSS 6.8
CVE-2015-5234 [MEDIUM] CVE-2015-5234: icedtea-web - IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize apple...
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.
Scope: local
bookworm: resolved (fixed in 1.6.1-1)
bullseye: resolved (fixed in 1.6.1-1)
forky: resolved (fixed in 1.6.1-1)
sid: resolved (fixed in 1.6.1-1)
trixie: resolved (fixed in 1.6.1-1)
GHSA
GHSA-vjh2-cm2h-354g: IcedTea-Web before 1
ghsa_unreviewed·2022-05-14
CVE-2015-5234 [MEDIUM] CWE-20 GHSA-vjh2-cm2h-354g: IcedTea-Web before 1
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.
OSV
icedtea-web vulnerabilities
osv·2015-11-24·CVSS 6.8
CVE-2015-5234 [MEDIUM] icedtea-web vulnerabilities
icedtea-web vulnerabilities
It was discovered that IcedTea Web incorrectly handled applet URLs. A
remote attacker could possibly use this issue to inject applets into the
.appletTrustSettings configuration file and bypass user approval.
(CVE-2015-5234)
Andrea Palazzo discovered that IcedTea Web incorrectly determined the
origin of unsigned applets. A remote attacker could possibly use this issue
to bypass user approval, or to trick the user into approving applet
execution. (CVE-2015-5235)
OSV
CVE-2015-5234: IcedTea-Web before 1
osv·2015-10-09·CVSS 6.8
CVE-2015-5234 [MEDIUM] CVE-2015-5234: IcedTea-Web before 1
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5235 CVE-2015-5234 icedtea-web: various flaws [fedora-all]
bugzilla·2015-09-02·CVSS 6.8
CVE-2015-5235 [MEDIUM] CVE-2015-5235 CVE-2015-5234 icedtea-web: various flaws [fedora-all]
CVE-2015-5235 CVE-2015-5234 icedtea-web: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Wh
Bugzilla
CVE-2015-5234 icedtea-web: unexpected permanent authorization of unsigned applets
bugzilla·2015-06-19·CVSS 6.8
CVE-2015-5234 [MEDIUM] CVE-2015-5234 icedtea-web: unexpected permanent authorization of unsigned applets
CVE-2015-5234 icedtea-web: unexpected permanent authorization of unsigned applets
Andrea Palazzo reported the following problem affecting IcedTea-Web:
"""
Permanent Trusted Applet Injection
Due to a lack of validation in the process of parsing non-standard uri schemes, it is possible to inject arbitrary trusted applets into the
.appletTrustSettings configuration file.
An attacker could exploit this flaw to permanently authorize the execution of unsigned applets in the context of a victim browser from arbitrary domains. It should be noted that the exploit is triggered even if the victim hits the "cancel" button when the authorization view is prompted.
"""
Acknowledgement:
Name: Andrea Palazzo (Truel IT)
Discussion:
Created attachment 1043118
patch for insertionof invald regex by mal
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167120.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167130.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00019.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2015-September/033546.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0778.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securitytracker.com/id/1033780http://www.ubuntu.com/usn/USN-2817-1https://bugzilla.redhat.com/show_bug.cgi?id=1233667http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167120.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167130.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00019.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2015-September/033546.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0778.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securitytracker.com/id/1033780http://www.ubuntu.com/usn/USN-2817-1https://bugzilla.redhat.com/show_bug.cgi?id=1233667
2015-10-09
Published