Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3149

Опубликовано: 20 апр. 2014
Источник: redhat
CVSS2: 3.3

Описание

The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5java-1.6.0-openjdkNot affected
Red Hat Enterprise Linux 5java-1.6.0-sunNot affected
Red Hat Enterprise Linux 5java-1.7.0-openjdkNot affected
Red Hat Enterprise Linux 5java-1.7.0-oracleNot affected
Red Hat Enterprise Linux 6java-1.6.0-openjdkNot affected
Red Hat Enterprise Linux 6java-1.6.0-sunNot affected
Red Hat Enterprise Linux 6java-1.7.0-openjdkNot affected
Red Hat Enterprise Linux 6java-1.7.0-oracleNot affected
Red Hat Enterprise Linux 6java-1.8.0-oracleNot affected
Red Hat Enterprise Linux 7java-1.6.0-openjdkNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=1213365OpenJDK8: insecure hsperfdata temporary file handling, CVE-2015-0383 regression (Hotspot)

3.3 Low

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 8 лет назад

The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack.

CVSS3: 5.5
nvd
около 8 лет назад

The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack.

CVSS3: 5.5
debian
около 8 лет назад

The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Li ...

CVSS3: 5.5
github
около 3 лет назад

The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack.

oracle-oval
около 10 лет назад

ELSA-2015-1228: java-1.8.0-openjdk security update (IMPORTANT)

3.3 Low

CVSS2