Bugzilla – Bug 863305
VUL-1: CVE-2014-1876: java-1_7_0-openjdk: insecure temp file handling in unpack200
Last modified: 2015-07-23 09:30:23 UTC
"Jakub Wilk reported in a Debian bug report that the unpack200 program included in OpenJDK did not properly handle the logfile properly. If the the log file was unable to be opened, it would create /tmp/unpack.log instead as the fallback, but do so in an insecure manner, as shown in unpack.cpp." See details at: http://seclists.org/oss-sec/2014/q1/242 CVE-2014-1876 was assigned to this issue. References: http://osvdb.org/102808 http://seclists.org/oss-sec/2014/q1/285 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1876 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-1876
bugbot adjusting priority
resolved, fixed and released