Bug 485116

Summary: IcedTea plugin allows applets to call System.exit()
Product: [Fedora] Fedora Reporter: Deepak Bhole <dbhole>
Component: java-1.6.0-openjdkAssignee: Deepak Bhole <dbhole>
Status: CLOSED CURRENTRELEASE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: low    
Version: 10CC: dbhole, langel, lkundrak, mjw
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2009-04-23 19:28:15 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Deepak Bhole 2009-02-11 17:27:21 UTC
An applet can call System.exit(), which in certain cases will cause the JVM to exit. Thus creating a potential DoS attack, as any other running applets will end up shutting down as well.

The fix is in the upstream repository, and need to be brought into Fedora (10 and Rawhide).

Comment 1 Deepak Bhole 2009-04-23 19:28:15 UTC
Fixed in all currently supported releases.