Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-2035

Опубликовано: 13 мая 2013
Источник: redhat
CVSS2: 3.3
EPSS Низкий

Описание

Race condition in hawtjni-runtime/src/main/java/org/fusesource/hawtjni/runtime/Library.java in HawtJNI before 1.8, when a custom library path is not specified, allows local users to execute arbitrary Java code by overwriting a temporary JAR file with a predictable name in /tmp.

The HawtJNI Library class wrote native libraries to a predictable file name in /tmp when the native libraries were bundled in a JAR file, and no custom library path was specified. A local attacker could overwrite these native libraries with malicious versions during the window between when HawtJNI writes them and when they are executed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1hawtjniWill not fix
OpenShift Enterprise 1jansiWill not fix
Red Hat JBoss Data Grid 6jansiAffected
Red Hat JBoss Enterprise Web Server 1amq-6.0Affected
Red Hat JBoss Enterprise Web Server 1fuse-6.0Affected
Red Hat JBoss Enterprise Web Server 1fuse-esb-7.1Affected
Red Hat JBoss Enterprise Web Server 1fuse-mc-7.1Affected
Red Hat JBoss Enterprise Web Server 1fuse-mq-7.1Affected
Red Hat JBoss Enterprise Web Server 1fuse-othersWill not fix
Red Hat JBoss SOA Platform 5jrubyWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=958618HawtJNI: predictable temporary file name leading to local arbitrary code execution

EPSS

Процентиль: 13%
0.00043
Низкий

3.3 Low

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

Race condition in hawtjni-runtime/src/main/java/org/fusesource/hawtjni/runtime/Library.java in HawtJNI before 1.8, when a custom library path is not specified, allows local users to execute arbitrary Java code by overwriting a temporary JAR file with a predictable name in /tmp.

nvd
больше 12 лет назад

Race condition in hawtjni-runtime/src/main/java/org/fusesource/hawtjni/runtime/Library.java in HawtJNI before 1.8, when a custom library path is not specified, allows local users to execute arbitrary Java code by overwriting a temporary JAR file with a predictable name in /tmp.

debian
больше 12 лет назад

Race condition in hawtjni-runtime/src/main/java/org/fusesource/hawtjni ...

github
больше 3 лет назад

Improper Control of Generation of Code in HawtJNI

EPSS

Процентиль: 13%
0.00043
Низкий

3.3 Low

CVSS2