SUSE-SU-2015:1689-1

    Dashboard / Vulnerabilities / SUSE-SU-2015:1689-1

    SUSE-SU-2015:1689-1

    Published: 16 Sept 2015Last Modified: 4 Feb 2026

    Summary: Security update for icedtea-web

    Details: The Java Plugin IcedTea Web was updated to 1.5.2, fixing bugs and security issues. * permissions sandbox and signed app and unsigned app with permissions all-permissions now run in sandbox instead of not at all. * fixed DownloadService * RH1231441 Unable to read the text of the buttons of the security dialogue * Fixed RH1233697 icedtea-web: applet origin spoofing (CVE-2015-5235, bsc#944208) * Fixed RH1233667 icedtea-web: unexpected permanent authorization of unsigned applets (CVE-2015-5234, bsc#944209) * MissingALACAdialog made available also for unsigned applications (but ignoring actual manifest value) and fixed

    Affected packages

    Package

    Name: icedtea-web

    Purl: pkg:rpm/suse/icedtea-web&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.5.3-0.9.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High