Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Ubuntu 15.10 & 14.04 USN-2817-1 Moderate: IcedTea Web Remote Code

ubuntu
Calendar Grey November 24, 2015
Scroller Ubuntu
Multiple IcedTea Web security flaws addressed in Ubuntu USN-2817-1 notice, improving software safety.
Several security issues were fixed in IcedTea Web.

Summary

Several security issues were fixed in IcedTea Web.

Software Description:

- icedtea-web: A web browser plugin to execute Java applets

Details:

It was discovered that IcedTea Web incorrectly handled applet URLs. A

remote attacker could possibly use this issue to inject applets into the

.appletTrustSettings configuration file and bypass user approval.

(CVE-2015-5234)

Andrea Palazzo discovered that IcedTea Web incorrectly determined the

origin of unsigned applets. A remote attacker could possibly use this issue

to bypass user approval, or to trick the user into approving applet

execution. (CVE-2015-5235)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  icedtea-7-plugin                1.5.3-0ubuntu0.15.10.1

Ubuntu 15.04:
  icedtea-7-plugin                1.5.3-0ubuntu0.15.04.1

Ubuntu 14.04 LTS:
  icedtea-6-plugin                1.5.3-0ubuntu0.14.04.1
  icedtea-7-plugin                1.5.3-0ubuntu0.14.04.1

After a standard system update you need to restart your browser to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2817-1

CVE-2015-5234, CVE-2015-5235

November 24, 2015

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.