IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.
CVSS Details
- CVSS 3.1 Base Score: 5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade icedtea-web | Jul 30, 2024 | Oct 9, 2015 |
| Oracle_linux | — | Upgrade icedtea-webUpgrade icedtea-web-javadoc | May 12, 2016 | Oct 9, 2015 |
| Suse | — | Upgrade java-1_8_0-openjdk-pluginUpgrade icedtea-web-javadocUpgrade java-1_7_0-openjdk-pluginUpgrade icedtea-web | Dec 18, 2015 | Oct 5, 2015 |
| Ubuntu | — | Upgrade icedtea-7-pluginUpgrade icedtea-6-plugin | Nov 30, 2015 | Oct 9, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub