PT-2015-3051 · Oracle · Openjdk
Publicado
2015-04-24
·
Atualizado
2015-11-10
·
CVE-2014-8873
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenJDK versions 7u79-2.5.5-1~deb8u1
Description
The issue is related to a .desktop file in the OpenJDK package, which includes a MIME type registration added to /etc/mailcap. This allows remote attackers to execute arbitrary code via a JAR file.
Recommendations
For OpenJDK version 7u79-2.5.5-1~deb8u1, consider removing the MIME type registration from /etc/mailcap to prevent exploitation until a patch is available. As a temporary workaround, restrict the execution of JAR files to minimize the risk of arbitrary code execution.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openjdk