Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Sat, 18 Jul 2015 14:13:26 +0200
From: Florian Weimer <>
Subject: CVE-2014-8873 was fixed in DSA-3235-1

We failed to mention in the original Debian security advisory that the
openjdk-7 update in DSA-3235-1 also fixed the following
Debian-specific vulnerability:

Some web browsers in Debian jessie would automatically execute
downloaded JAR files, without any kind of sandbox.  Presumably, that
affects email clients as well.

We have tracked this down to the /etc/mailcap entry generated from the
openjdk-7 .desktop file, after this change in mime-support (which is
specific to Debian and its downstreams):

mime-support (3.53) unstable; urgency=low

  801bd8b Parse Desktop entries to generate mailcap entries.
          Patch from Brian M. Carlson. (Closes: #497779)

 -- Charles Plessy <>  Sun, 05 May 2013 17:24:50 +0900

This change is part of Debian jessie, previous releases are not

After consultation with the mime-support maintainers, the resolution
in DSA-3235-1 removes the MIME type registration from the openjdk-7
package.  Auto-generation of /etc/mailcap from .desktop files remains
the intended behavior of the mime-support package.

The unintended code execution was reported initially to MITRE by
Alexander Neumann, and MITRE assigned CVE-2014-8873 to this issue,
without a full root cause analysis, incorrectly assuming it was a w3m
(and not Debian) vulnerability.

For other packages with .desktop files affected in the same way, we
will assign separate CVE IDs from Debian's pool.  We do not believe
any of the affected packages are in the supported package set of any
Debian downstream.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.