First published: Mon Nov 09 2015(Updated: )
A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary code via a JAR file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJDK 17 | =1.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-8873 has been classified as a high severity vulnerability due to its potential to allow remote code execution.
To address CVE-2014-8873, it is recommended to update the openjdk package to a version that is not vulnerable.
CVE-2014-8873 specifically affects the OpenJDK version 1.7.0, notably in the Debian package.
CVE-2014-8873 allows remote attackers to execute arbitrary code through a specially crafted JAR file.
Yes, CVE-2014-8873 is primarily related to the Debian operating system's implementation of OpenJDK.