Описание
A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needed | |
| jammy | released | 3.70+nmu1ubuntu1.22.04.1 |
| noble | released | 3.70+nmu1ubuntu1.24.04.1 |
| questing | released | 3.74ubuntu1.1 |
| resolute | released | 3.75ubuntu1.1 |
| upstream | not-affected | code not present |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-apps/focal | ignored | superseded by openjdk-17 |
| jammy | DNE | |
| noble | DNE | |
| questing | DNE | |
| resolute | DNE | |
| upstream | not-affected | code not present |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-apps/focal | ignored | superseded by openjdk-17 |
| jammy | DNE | |
| noble | DNE | |
| questing | DNE | |
| resolute | DNE | |
| upstream | not-affected | code not present |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps/bionic | not-affected | code not present |
| esm-apps/focal | not-affected | code not present |
| esm-apps/jammy | not-affected | mailcap update prevents it |
| esm-apps/resolute | not-affected | mailcap update prevents it |
| jammy | not-affected | mailcap update prevents it |
| noble | not-affected | mailcap update prevents it |
| questing | not-affected | mailcap update prevents it |
| resolute | not-affected | mailcap update prevents it |
| upstream | not-affected | code not present |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps/resolute | not-affected | mailcap update prevents it |
| jammy | DNE | |
| noble | DNE | |
| questing | not-affected | mailcap update prevents it |
| resolute | not-affected | mailcap update prevents it |
| upstream | not-affected | code not present |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| jammy | ignored | superseded by openjdk-19 |
| noble | DNE | |
| questing | DNE | |
| resolute | DNE | |
| upstream | not-affected | code not present |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps/focal | not-affected | code not present |
| esm-apps/jammy | not-affected | mailcap update prevents it |
| esm-apps/resolute | not-affected | mailcap update prevents it |
| jammy | not-affected | mailcap update prevents it |
| noble | not-affected | mailcap update prevents it |
| questing | not-affected | mailcap update prevents it |
| resolute | not-affected | mailcap update prevents it |
| upstream | not-affected | code not present |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps/resolute | not-affected | mailcap update prevents it |
| jammy | DNE | |
| noble | DNE | |
| questing | not-affected | mailcap update prevents it |
| resolute | not-affected | mailcap update prevents it |
| upstream | not-affected | code not present |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| jammy | not-affected | mailcap update prevents it |
| noble | not-affected | mailcap update prevents it |
| questing | not-affected | mailcap update prevents it |
| resolute | not-affected | mailcap update prevents it |
| upstream | not-affected | code not present |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps/bionic | not-affected | code not present |
| esm-apps/focal | not-affected | code not present |
| esm-apps/jammy | not-affected | mailcap update prevents it |
| esm-apps/noble | not-affected | mailcap update prevents it |
| esm-apps/resolute | not-affected | mailcap update prevents it |
| esm-infra-legacy/xenial | not-affected | code not present |
| jammy | not-affected | mailcap update prevents it |
| noble | not-affected | mailcap update prevents it |
| questing | not-affected | mailcap update prevents it |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-apps-legacy/xenial | ignored | no longer supported by upstream |
| jammy | DNE | |
| noble | DNE | |
| questing | DNE | |
| resolute | DNE | |
| upstream | not-affected | code not present |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps/noble | not-affected | mailcap update prevents it |
| esm-apps/resolute | not-affected | mailcap update prevents it |
| esm-infra/bionic | not-affected | code not present |
| esm-infra/focal | not-affected | code not present |
| jammy | not-affected | mailcap update prevents it |
| noble | not-affected | mailcap update prevents it |
| questing | not-affected | mailcap update prevents it |
| resolute | not-affected | mailcap update prevents it |
| upstream | not-affected | code not present |
Показывать по
8.8 High
CVSS3
Связанные уязвимости
A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.
A sandbox escape vulnerability exists in the OpenJDK packages provided ...
A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.
8.8 High
CVSS3