CVE-2014-1876
Publication date 10 February 2014
Last updated 24 July 2024
Ubuntu priority
The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 does not securely create temporary files when a log file cannot be opened, which allows local users to overwrite arbitrary files via a symlink attack on /tmp/unpack.log.
Status
Package | Ubuntu Release | Status |
---|---|---|
openjdk-6 | 14.04 LTS trusty | Not in release |
openjdk-7 | 14.04 LTS trusty |
Fixed 7u55-2.4.7-1ubuntu1
|
Notes
References
Related Ubuntu Security Notices (USN)
- USN-2187-1
- OpenJDK 7 vulnerabilities
- 30 April 2014
- USN-2191-1
- OpenJDK 6 vulnerabilities
- 1 May 2014