CVE Database
/

CVE-2014-1876

Back to search

CVE-2014-1876

Published: Feb 10, 2014

Modified: Aug 6, 2024

PUBLISHED

Description

The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 does not securely create temporary files when a log file cannot be opened, which allows local users to overwrite arbitrary files via a symlink attack on /tmp/unpack.log.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-2187-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2014:0675
vendor-advisory
x_refsource_REDHAT
RHSA-2014:0414
vendor-advisory
x_refsource_REDHAT
GLSA-201406-32
vendor-advisory
x_refsource_GENTOO
USN-2191-1
vendor-advisory
x_refsource_UBUNTU
HPSBUX03091
vendor-advisory
x_refsource_HP
RHSA-2014:0413
vendor-advisory
x_refsource_REDHAT
59058
third-party-advisory
x_refsource_SECUNIA
SSRT101667
vendor-advisory
x_refsource_HP
HPSBUX03092
vendor-advisory
x_refsource_HP
RHSA-2014:0685
vendor-advisory
x_refsource_REDHAT
DSA-2912
vendor-advisory
x_refsource_DEBIAN
58415
third-party-advisory
x_refsource_SECUNIA
SSRT101668
vendor-advisory
x_refsource_HP
65568
vdb-entry
x_refsource_BID
102808
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now