UBUNTU-CVE-2014-1876
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-1876
UBUNTU-CVE-2014-1876
Summary:
Details: The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 does not securely create temporary files when a log file cannot be opened, which allows local users to overwrite arbitrary files via a symlink attack on /tmp/unpack.log.
References: https://ubuntu.com/security/CVE-2014-1876, https://bugzilla.redhat.com/show_bug.cgi?id=1060907, http://seclists.org/oss-sec/2014/q1/285, http://seclists.org/oss-sec/2014/q1/242, http://osvdb.org/102808, http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737562, https://ubuntu.com/security/notices/USN-2187-1, https://ubuntu.com/security/notices/USN-2191-1, https://www.cve.org/CVERecord?id=CVE-2014-1876
Affected packages
Package
Name: openjdk-7
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
