Andrea Palazzo reported the following problem affecting IcedTea-Web:
""" Permanent Trusted Applet Injection
Due to a lack of validation in the process of parsing non-standard uri schemes, it is possible to inject arbitrary trusted applets into the .appletTrustSettings configuration file.
An attacker could exploit this flaw to permanently authorize the execution of unsigned applets in the context of a victim browser from arbitrary domains. It should be noted that the exploit is triggered even if the victim hits the "cancel" button when the authorization view is prompted. """
Acknowledgement:
Name: Andrea Palazzo (Truel IT)
Andrea Palazzo reported the following problem affecting IcedTea-Web:
""" When requesting authorization to run an unsigned applet, a warning message is prompted, indicating the domain from which the applet's code is being requested. It is possible to tamper with this value just supplying an arbitrary value as codebase. This issue could be exploited to abuse the eventual presence of whitelisted domains in the victim config (something like A 1434665367633 . \Qhttp://trusted-site/\E) to gain unauthorized execution or to trick the user into allowing an application leveraging on the trust he could have for a well known domain. """
Acknowledgement:
Name: Andrea Palazzo (Truel IT)