[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-1876Date: (C)2014-02-11   (M)2024-03-22


The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 does not securely create temporary files when a log file cannot be opened, which allows local users to overwrite arbitrary files via a symlink attack on /tmp/unpack.log.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.4
Exploit Score: 3.4
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
OSVDB-102808
SECUNIA-58415
SECUNIA-59058
BID-65568
DSA-2912
GLSA-201406-32
RHSA-2014:0413
RHSA-2014:0414
RHSA-2014:0675
RHSA-2014:0685
SSRT101667
SSRT101668
USN-2187-1
USN-2191-1
http://seclists.org/oss-sec/2014/q1/242
http://seclists.org/oss-sec/2014/q1/285
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737562
http://www-01.ibm.com/support/docview.wss?uid=swg21672080
http://www-01.ibm.com/support/docview.wss?uid=swg21676746
http://www-01.ibm.com/support/docview.wss?uid=swg21679713
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html
https://bugzilla.redhat.com/show_bug.cgi?id=1060907

CPE    3
cpe:/a:oracle:openjdk:1.7.0
cpe:/a:oracle:openjdk:1.6.0
cpe:/a:oracle:openjdk:1.8.0
CWE    1
CWE-59
OVAL    30
oval:org.secpod.oval:def:1600146
oval:org.secpod.oval:def:1600047
oval:org.secpod.oval:def:501224
oval:org.secpod.oval:def:501223
...

© SecPod Technologies