Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

openSUSE 13.2: openSUSE-SU-2015:1595-1 Important Icedtea-Web Security Fix

opensuse
Calendar Grey September 22, 2015
Scroller Opensuse
openSUSE Security Update: Security update for icedtea-web __________________________________________
An update that solves three vulnerabilities and has one An update that solves three vulnerabilities and has one An update that solves three vulnerabilities and has one errata is no...

Description

The icedtea-web java plugin was updated to 1.6.1.

Changes included:

* Enabled Entry-Point attribute check

* permissions sandbox and signed app and unsigned app with permissions

all-permissions now run in sandbox instead of not at all.

* fixed DownloadService

* comments in deployment.properties now should persists load/save

* fixed bug in caching of files with query

* fixed issues with recreating of existing shortcut

* trustAll/trustNone now processed correctly

* headless no longer shows dialogues

* RH1231441 Unable to read the text of the buttons of the security dialogue

* Fixed RH1233697 icedtea-web: applet origin spoofing (CVE-2015-5235,

bsc#944208)

* Fixed RH1233667 icedtea-web: unexpected permanent authorization of

unsigned applets (CVE-2015-5234, bsc#944209)

* MissingALACAdialog made available also for unsigned applications (but

ignoring actual manifest value) and fixed

* NetX

- fixed issues with -html...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.2:

zypper in -t patch openSUSE-2015-602=1

- openSUSE 13.1:

zypper in -t patch openSUSE-2015-602=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.2 (i586 x86_64):

java-1_7_0-openjdk-plugin-1.6.1-6.1

java-1_7_0-openjdk-plugin-debuginfo-1.6.1-6.1

java-1_7_0-openjdk-plugin-debugsource-1.6.1-6.1

java-1_8_0-openjdk-plugin-1.6.1-6.2

java-1_8_0-openjdk-plugin-debuginfo-1.6.1-6.2

java-1_8_0-openjdk-plugin-debugsource-1.6.1-6.2

- openSUSE 13.2 (noarch):

icedtea-web-javadoc-1.6.1-6.1

- openSUSE 13.1 (i586 x86_64):

icedtea-web-1.5.3-0.7.1

icedtea-web-debuginfo-1.5.3-0.7.1

icedtea-web-debugsource-1.5.3-0.7.1

- openSUSE 13.1 (noarch):

icedtea-web-javadoc-1.5.3-0.7.1

References

https://www.suse.com/security/cve/CVE-2012-4540.html

https://www.suse.com/security/cve/CVE-2015-5234.html

https://www.suse.com/security/cve/CVE-2015-5235.html

https://bugzilla.suse.com/show_bug.cgi?id=755054

https://bugzilla.suse.com/show_bug.cgi?id=830880

https://bugzilla.suse.com/show_bug.cgi?id=944208

https://bugzilla.suse.com/show_bug.cgi?id=944209

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2015:1595-1
Rating: important
Affected Products: openSUSE 13.2 openSUSE 13.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.