Описание
Race condition in hawtjni-runtime/src/main/java/org/fusesource/hawtjni/runtime/Library.java in HawtJNI before 1.8, when a custom library path is not specified, allows local users to execute arbitrary Java code by overwriting a temporary JAR file with a predictable name in /tmp.
The HawtJNI Library class wrote native libraries to a predictable file name in /tmp when the native libraries were bundled in a JAR file, and no custom library path was specified. A local attacker could overwrite these native libraries with malicious versions during the window between when HawtJNI writes them and when they are executed.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Enterprise 1 | hawtjni | Will not fix | ||
| OpenShift Enterprise 1 | jansi | Will not fix | ||
| Red Hat JBoss Data Grid 6 | jansi | Affected | ||
| Red Hat JBoss Enterprise Web Server 1 | amq-6.0 | Affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-6.0 | Affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-esb-7.1 | Affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-mc-7.1 | Affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-mq-7.1 | Affected | ||
| Red Hat JBoss Enterprise Web Server 1 | fuse-others | Will not fix | ||
| Red Hat JBoss SOA Platform 5 | jruby | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS2
Связанные уязвимости
Race condition in hawtjni-runtime/src/main/java/org/fusesource/hawtjni/runtime/Library.java in HawtJNI before 1.8, when a custom library path is not specified, allows local users to execute arbitrary Java code by overwriting a temporary JAR file with a predictable name in /tmp.
Race condition in hawtjni-runtime/src/main/java/org/fusesource/hawtjni/runtime/Library.java in HawtJNI before 1.8, when a custom library path is not specified, allows local users to execute arbitrary Java code by overwriting a temporary JAR file with a predictable name in /tmp.
Race condition in hawtjni-runtime/src/main/java/org/fusesource/hawtjni ...
EPSS
3.3 Low
CVSS2