CVE-2014-8873
Published: 9 November 2015
A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary code via a JAR file.
Notes
Author | Note |
---|---|
tyhicks | Ubuntu is not affected due to our policy that prohibits desktop files from directly executing files that don't have the executable bit set (https://wiki.ubuntu.com/SecurityTeam/Policies#Execute-Permission_Bit_Required) |
Priority
Status
Package | Release | Status |
---|---|---|
icedtea-web Launchpad, Ubuntu, Debian |
precise |
Not vulnerable
|
trusty |
Does not exist
(trusty was not-affected)
|
|
upstream |
Needs triage
|
|
utopic |
Not vulnerable
|
|
vivid |
Not vulnerable
|
|
openjdk-6 Launchpad, Ubuntu, Debian |
precise |
Not vulnerable
|
trusty |
Does not exist
(trusty was not-affected)
|
|
upstream |
Needs triage
|
|
utopic |
Not vulnerable
|
|
vivid |
Not vulnerable
|
|
openjdk-7 Launchpad, Ubuntu, Debian |
precise |
Not vulnerable
|
trusty |
Does not exist
(trusty was not-affected)
|
|
upstream |
Needs triage
|
|
utopic |
Not vulnerable
|
|
vivid |
Not vulnerable
|
|
openjdk-8 Launchpad, Ubuntu, Debian |
precise |
Does not exist
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
utopic |
Not vulnerable
|
|
vivid |
Not vulnerable
|