4.4
CVSSv2

CVE-2014-1876

Published: 10/02/2014 Updated: 05/01/2018
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The unpacker::redirect_stdio function in unpack.cpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 5.0u61, 6u71, 7u51, and 8; JRockit R27.8.1 and R28.3.1; and Java SE Embedded 7u51 does not securely create temporary files when a log file cannot be opened, which allows local users to overwrite arbitrary files via a symlink attack on /tmp/unpack.log.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle openjdk 1.8.0

oracle openjdk 1.6.0

oracle openjdk 1.7.0

Vendor Advisories

Debian Bug report logs - #737562 unpack200: CVE-2014-1876: insecure use of /tmp Package: openjdk-7-jre-headless; Maintainer for openjdk-7-jre-headless is OpenJDK Team <openjdk@listslaunchpadnet>; Source for openjdk-7-jre-headless is src:openjdk-7 (PTS, buildd, popcon) Reported by: Jakub Wilk <jwilk@debianorg> Date ...
Several security issues were fixed in OpenJDK 7 ...
Several security issues were fixed in OpenJDK 6 ...
An input validation flaw was discovered in the medialib library in the 2D component A specially crafted image could trigger Java Virtual Machine memory corruption when processed A remote attacker, or an untrusted Java application or applet, could possibly use this flaw to execute arbitrary code with the privileges of the user running the Java Vir ...
An input validation flaw was discovered in the medialib library in the 2D component A specially crafted image could trigger Java Virtual Machine memory corruption when processed A remote attacker, or an untrusted Java application or applet, could possibly use this flaw to execute arbitrary code with the privileges of the user running the Java Vir ...
The unpacker::redirect_stdio function in unpackcpp in unpack200 in OpenJDK 6, 7, and 8; Oracle Java SE 50u61, 6u71, 7u51, and 8; JRockit R2781 and R2831; and Java SE Embedded 7u51 does not securely create temporary files when a log file cannot be opened, which allows local users to overwrite arbitrary files via a symlink attack on /tmp/unpack ...