Insecure temporary files In java-1.6.0-openjdk
Description
The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 does not securely create temporary files when a log file cannot be opened, which allows local users to overwrite arbitrary files via a symlink attack on /tmp/unpack.log.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel7 | 1:1.6.0.0-6.1.13.3.el7_0 | ||
rpm rhel7 | 1:1.7.0.55-2.4.7.2.el7_0 | ||
rpm rhel5 | 1:1.7.0.55-2.4.7.1.el5_10 | ||
rpm rhel7 | - | - | |
rpm rhel5 | 1:1.6.0.0-5.1.13.3.el5_10 | ||
rpm rhel6 | 1:1.6.0.0-5.1.13.3.el6_5 | ||
rpm rhel6 | 1:1.7.0.55-2.4.7.1.el6_5 |
Aliases
1. 2. 3.