Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-2027

Опубликовано: 13 фев. 2015
Источник: debian

Описание

Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jythonfixed2.7.0+repack-1experimentalpackage
jythonfixed2.7.1+repack-1package
jythonignoredstretchpackage
jythonignoredjessiepackage
jythonno-dsawheezypackage
jythonno-dsasqueezepackage

Примечания

  • http://bugs.jython.org/issue2044

  • The original issue seem addressed in 2.7.0+repack-1, but still files

  • might be created/written to /usr/share/jython/cachedir/packages

  • which should not be in /usr beeing a cachedir.

Связанные уязвимости

ubuntu
почти 11 лет назад

Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.

redhat
почти 13 лет назад

Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.

nvd
почти 11 лет назад

Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.

github
больше 3 лет назад

Jython Improper Access Restrictions vulnerability