UbuntuUpdates.org

Package "icedtea-web"

Name: icedtea-web

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • web browser plugin based on OpenJDK and IcedTea to execute Java applets
  • NetX - implementation of the Java Network Launching Protocol (JNLP)
  • NetX - implementation of the Java Network Launching Protocol (JNLP)
  • web browser plugin to execute Java applets (dependency package)

Latest version: 1.5.3-0ubuntu0.14.04.1
Release: trusty (14.04)
Level: updates
Repository: main

Links



Other versions of "icedtea-web" in Trusty

Repository Area Version
base main 1.5-1ubuntu1
base universe 1.5-1ubuntu1
security main 1.5.3-0ubuntu0.14.04.1
security universe 1.5.3-0ubuntu0.14.04.1
updates universe 1.5.3-0ubuntu0.14.04.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.5.3-0ubuntu0.14.04.1 2015-11-24 20:06:38 UTC

  icedtea-web (1.5.3-0ubuntu0.14.04.1) trusty-security; urgency=medium

  * Updated to upstream version 1.5.3 to fix two security issues:
    - CVE-2015-5234: applet URL sanitization issue
    - CVE-2015-5235: unsigned applet origin issue

 -- Marc Deslauriers Fri, 20 Nov 2015 13:37:54 -0500

CVE-2015-5234 IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .app
CVE-2015-5235 IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass t



About   -   Send Feedback to @ubuntu_updates