CVE-2015-5235
published 2015-10-09CVE-2015-5235: IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.02%
86.0th percentile
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | icedtea-web | < icedtea-web 1.6.1-1 (bookworm) | icedtea-web 1.6.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| redhat | icedtea | <= 1.5.2 | — |
| redhat | icedtea | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.8MEDIUM
vendor_ubuntu6.8MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
IcedTea Web vulnerabilities
vendor_ubuntu·2015-11-24·CVSS 6.8
CVE-2015-5234 [MEDIUM] IcedTea Web vulnerabilities
Title: IcedTea Web vulnerabilities
Summary: Several security issues were fixed in IcedTea Web.
It was discovered that IcedTea Web incorrectly handled applet URLs. A
remote attacker could possibly use this issue to inject applets into the
.appletTrustSettings configuration file and bypass user approval.
(CVE-2015-5234)
Andrea Palazzo discovered that IcedTea Web incorrectly determined the
origin of unsigned applets. A remote attacker could possibly use this issue
to bypass user approval, or to trick the user into approving applet
execution. (CVE-2015-5235)
Instructions: After a standard system update you need to restart your browser to make
all the necessary changes.
Red Hat
icedtea-web: applet origin spoofing
vendor_redhat·2015-09-02·CVSS 4.3
CVE-2015-5235 [MEDIUM] CWE-345 icedtea-web: applet origin spoofing
icedtea-web: applet origin spoofing
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.
It was discovered that IcedTea-Web did not properly determine an applet's origin when asking the user if the applet should be run. A malicious page could use this flaw to cause IcedTea-Web to execute the applet without user approval, or confuse the user into approving applet execution based on an incorrectly indicated applet origin.
Debian
CVE-2015-5235: icedtea-web - IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the ...
vendor_debian·2015·CVSS 4.3
CVE-2015-5235 [MEDIUM] CVE-2015-5235: icedtea-web - IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the ...
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.
Scope: local
bookworm: resolved (fixed in 1.6.1-1)
bullseye: resolved (fixed in 1.6.1-1)
forky: resolved (fixed in 1.6.1-1)
sid: resolved (fixed in 1.6.1-1)
trixie: resolved (fixed in 1.6.1-1)
GHSA
GHSA-c7wx-r8q7-fmcf: IcedTea-Web before 1
ghsa_unreviewed·2022-05-14
CVE-2015-5235 [MEDIUM] CWE-20 GHSA-c7wx-r8q7-fmcf: IcedTea-Web before 1
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.
OSV
icedtea-web vulnerabilities
osv·2015-11-24·CVSS 6.8
CVE-2015-5234 [MEDIUM] icedtea-web vulnerabilities
icedtea-web vulnerabilities
It was discovered that IcedTea Web incorrectly handled applet URLs. A
remote attacker could possibly use this issue to inject applets into the
.appletTrustSettings configuration file and bypass user approval.
(CVE-2015-5234)
Andrea Palazzo discovered that IcedTea Web incorrectly determined the
origin of unsigned applets. A remote attacker could possibly use this issue
to bypass user approval, or to trick the user into approving applet
execution. (CVE-2015-5235)
OSV
CVE-2015-5235: IcedTea-Web before 1
osv·2015-10-09·CVSS 4.3
CVE-2015-5235 [MEDIUM] CVE-2015-5235: IcedTea-Web before 1
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5235 CVE-2015-5234 icedtea-web: various flaws [fedora-all]
bugzilla·2015-09-02·CVSS 6.8
CVE-2015-5235 [MEDIUM] CVE-2015-5235 CVE-2015-5234 icedtea-web: various flaws [fedora-all]
CVE-2015-5235 CVE-2015-5234 icedtea-web: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Wh
Bugzilla
CVE-2015-5235 icedtea-web: applet origin spoofing
bugzilla·2015-06-19·CVSS 4.3
CVE-2015-5235 [MEDIUM] CVE-2015-5235 icedtea-web: applet origin spoofing
CVE-2015-5235 icedtea-web: applet origin spoofing
Andrea Palazzo reported the following problem affecting IcedTea-Web:
"""
When requesting authorization to run an unsigned applet, a warning message is prompted, indicating the domain from which the applet's code is being requested. It is possible to tamper with this value just supplying an arbitrary value as codebase. This issue could be exploited to abuse the eventual presence of whitelisted domains in the victim config (something like A 1434665367633 .* \Qhttp://trusted-site/\E) to gain unauthorized execution or to trick the user into allowing an application leveraging on the trust he could have for a well known domain.
"""
Acknowledgement:
Name: Andrea Palazzo (Truel IT)
Discussion:
This is nice example, where http://docs.oracle.co
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167120.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167130.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00019.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2015-September/033546.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0778.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securitytracker.com/id/1033780http://www.ubuntu.com/usn/USN-2817-1https://bugzilla.redhat.com/show_bug.cgi?id=1233697http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167120.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167130.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00019.htmlhttp://mail.openjdk.java.net/pipermail/distro-pkg-dev/2015-September/033546.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0778.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securitytracker.com/id/1033780http://www.ubuntu.com/usn/USN-2817-1https://bugzilla.redhat.com/show_bug.cgi?id=1233697
2015-10-09
Published