Описание
The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 does not securely create temporary files when a log file cannot be opened, which allows local users to overwrite arbitrary files via a symlink attack on /tmp/unpack.log.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | java-1.6.0-ibm | Affected | ||
Red Hat Enterprise Linux 7 | java-1.6.0-sun | Not affected | ||
Red Hat Enterprise Linux 7 | java-1.7.0-oracle | Not affected | ||
Oracle Java for Red Hat Enterprise Linux 5 | java-1.7.0-oracle | Fixed | RHSA-2014:0413 | 17.04.2014 |
Oracle Java for Red Hat Enterprise Linux 5 | java-1.6.0-sun | Fixed | RHSA-2014:0414 | 17.04.2014 |
Oracle Java for Red Hat Enterprise Linux 6 | java-1.7.0-oracle | Fixed | RHSA-2014:0413 | 17.04.2014 |
Oracle Java for Red Hat Enterprise Linux 6 | java-1.6.0-sun | Fixed | RHSA-2014:0414 | 17.04.2014 |
Red Hat Enterprise Linux 5 | java-1.7.0-openjdk | Fixed | RHSA-2014:0407 | 16.04.2014 |
Red Hat Enterprise Linux 5 | java-1.6.0-openjdk | Fixed | RHSA-2014:0408 | 16.04.2014 |
Red Hat Enterprise Linux 6 | java-1.7.0-openjdk | Fixed | RHSA-2014:0406 | 16.04.2014 |
Показывать по
Дополнительная информация
Статус:
EPSS
1.9 Low
CVSS2
Связанные уязвимости
The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 does not securely create temporary files when a log file cannot be opened, which allows local users to overwrite arbitrary files via a symlink attack on /tmp/unpack.log.
The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 does not securely create temporary files when a log file cannot be opened, which allows local users to overwrite arbitrary files via a symlink attack on /tmp/unpack.log.
The unpacker::redirect_stdio function in unpack.cpp in unpack200 in Op ...
The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 does not securely create temporary files when a log file cannot be opened, which allows local users to overwrite arbitrary files via a symlink attack on /tmp/unpack.log.
Уязвимость средства разработки приложений Java Development Kit, позволяющая локальному пользователю заменить произвольные файлы
EPSS
1.9 Low
CVSS2