PT-2015-3051 · Oracle · Openjdk

Publicado

2015-04-24

·

Atualizado

2015-11-10

·

CVE-2014-8873

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenJDK versions 7u79-2.5.5-1~deb8u1
Description The issue is related to a .desktop file in the OpenJDK package, which includes a MIME type registration added to /etc/mailcap. This allows remote attackers to execute arbitrary code via a JAR file.
Recommendations For OpenJDK version 7u79-2.5.5-1~deb8u1, consider removing the MIME type registration from /etc/mailcap to prevent exploitation until a patch is available. As a temporary workaround, restrict the execution of JAR files to minimize the risk of arbitrary code execution.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-00256
CVE-2014-8873
DSA-3235-1
DSA-3316-1

Produtos afetados

Openjdk