Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-8873

Опубликовано: 09 нояб. 2015
Источник: debian

Описание

A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary code via a JAR file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openjdk-8fixed8u45-b14-1package
openjdk-7fixed7u79-2.5.5-1package
openjdk-7not-affectedwheezypackage
openjdk-7not-affectedsqueezepackage
openjdk-6removedpackage
openjdk-6not-affectedwheezypackage
openjdk-6not-affectedsqueezepackage

Примечания

  • Starting with mime-support 3.53, MimeType entries in desktop

  • files end up in /etc/mailcap, which introduces the user-initiated

  • code execution.

Связанные уязвимости

ubuntu
около 10 лет назад

A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary code via a JAR file.

nvd
около 10 лет назад

A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary code via a JAR file.

github
больше 3 лет назад

A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary code via a JAR file.

fstec
около 10 лет назад

Уязвимость комплекта разработчика приложений OpenJDK, позволяющая нарушителю выполнить произвольный код