MGASA-2014-0461

Source
https://advisories.mageia.org/MGASA-2014-0461.html
Import Source
https://advisories.mageia.org/MGASA-2014-0461.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2014-0461
Related
Published
2014-11-21T12:44:16Z
Modified
2014-11-21T11:54:26Z
Summary
Updated hawtjni packages fix security vulnerability
Details

The HawtJNI Library class wrote native libraries to a predictable file name in /tmp/ when the native libraries were bundled in a JAR file, and no custom library path was specified. A local attacker could overwrite these native libraries with malicious versions during the window between when HawtJNI writes them and when they are executed (CVE-2013-2035).

References
Credits

Affected packages

Mageia:3 / hawtjni

Package

Name
hawtjni
Purl
pkg:rpm/mageia/hawtjni?distro=mageia-3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9-1.mga3

Ecosystem specific

{
    "section": "core"
}