CVE-2014-8873: Input Validation
Published Nov 9, 2015
·Updated
A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary code via a JAR file.
Affected Software
1 affected component
ORACLE OpenJDK=1.7.0
Event History
Nov 9, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8873?
CVE-2014-8873 has been classified as a high severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2014-8873?
To address CVE-2014-8873, it is recommended to update the openjdk package to a version that is not vulnerable.
3
Which versions of OpenJDK are affected by CVE-2014-8873?
CVE-2014-8873 specifically affects the OpenJDK version 1.7.0, notably in the Debian package.
4
What type of attack does CVE-2014-8873 allow?
CVE-2014-8873 allows remote attackers to execute arbitrary code through a specially crafted JAR file.
5
Is CVE-2014-8873 specific to a certain operating system?
Yes, CVE-2014-8873 is primarily related to the Debian operating system's implementation of OpenJDK.