---
title: "CVE-2015-5234\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2015-5234?format=md
keywords: index, follow
---

# CVE-2015-5234

Publication date 9 October 2015

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize
applet URLs, which allows remote attackers to inject applets into the
.appletTrustSettings configuration file and bypass user approval to execute
the applet via a crafted web page, possibly related to line breaks.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2015-5234?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| icedtea-web | 15.10 wily | Fixed 1.5.3-0ubuntu0.15.10.1 |
| 15.04 vivid | Fixed 1.5.3-0ubuntu0.15.04.1 |
| 14.04 LTS trusty | Fixed 1.5.3-0ubuntu0.14.04.1 |
| 12.04 LTS precise | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2015-5234?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

extended applets security was introduced in icedtea-web 1.4

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| icedtea-web | * Upstream:   <http://icedtea.classpath.org/hg/icedtea-web/rev/53500e3de1bc> * Upstream:   <http://icedtea.classpath.org/hg/icedtea-web/rev/c9befa549f63> * Upstream:   <http://icedtea.classpath.org/hg/icedtea-web/rev/5ddfe3e389ab> * Upstream:   <http://icedtea.classpath.org/hg/icedtea-web/rev/1a1cbf3b1123> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5234)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2015-5234)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2015-5234)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2015-5234)

### Related Ubuntu Security Notices (USN)

+ [USN-2817-1](https://usn.ubuntu.com/USN-2817-1)
+ IcedTea Web vulnerabilities
+ 24 November 2015

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2015-5234>
