CVE-2015-5234: Fedoraproject Fedora
Medium severity, CVSS 6.8. EPSS: 2.1% chance of exploitation in the next 30 days.
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.
Affected products
- Fedoraproject Fedora: version 21 only; version 22 only
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Red Hat Enterprise Linux Desktop: version 6.0 only
- Red Hat Enterprise Linux Hpc Node: version 6.0 only
- Red Hat Enterprise Linux Server: version 6.0 only
- Red Hat Enterprise Linux Workstation: version 6.0 only
- Red Hat Icedtea: up to and including 1.5.2; version 1.6 only
Published 2015-10-09. Last modified 2026-06-17.