SUSE-SU-2015:1689-1
Dashboard / Vulnerabilities / SUSE-SU-2015:1689-1
SUSE-SU-2015:1689-1
Summary: Security update for icedtea-web
Details: The Java Plugin IcedTea Web was updated to 1.5.2, fixing bugs and security issues. * permissions sandbox and signed app and unsigned app with permissions all-permissions now run in sandbox instead of not at all. * fixed DownloadService * RH1231441 Unable to read the text of the buttons of the security dialogue * Fixed RH1233697 icedtea-web: applet origin spoofing (CVE-2015-5235, bsc#944208) * Fixed RH1233667 icedtea-web: unexpected permanent authorization of unsigned applets (CVE-2015-5234, bsc#944209) * MissingALACAdialog made available also for unsigned applications (but ignoring actual manifest value) and fixed
References: https://www.suse.com/support/update/announcement/2015/suse-su-20151689-1/, https://bugzilla.suse.com/944208, https://bugzilla.suse.com/944209, https://www.suse.com/security/cve/CVE-2015-5234, https://www.suse.com/security/cve/CVE-2015-5235
Affected packages
Package
Name: icedtea-web
Purl: pkg:rpm/suse/icedtea-web&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
