UbuntuUpdates.org

Package "icedtea-netx"

Name: icedtea-netx

Description:

NetX - implementation of the Java Network Launching Protocol (JNLP)

Latest version: 1.5.3-0ubuntu0.14.04.1
Release: trusty (14.04)
Level: updates
Repository: main
Head package: icedtea-web
Homepage: http://icedtea.classpath.org/wiki/IcedTea-Web

Links


Download "icedtea-netx"


Other versions of "icedtea-netx" in Trusty

Repository Area Version
base main 1.5-1ubuntu1
security main 1.5.3-0ubuntu0.14.04.1

Changelog

Version: 1.5.3-0ubuntu0.14.04.1 2015-11-24 20:06:38 UTC

  icedtea-web (1.5.3-0ubuntu0.14.04.1) trusty-security; urgency=medium

  * Updated to upstream version 1.5.3 to fix two security issues:
    - CVE-2015-5234: applet URL sanitization issue
    - CVE-2015-5235: unsigned applet origin issue

 -- Marc Deslauriers Fri, 20 Nov 2015 13:37:54 -0500

CVE-2015-5234 IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .app
CVE-2015-5235 IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass t



About   -   Send Feedback to @ubuntu_updates