CVE-2013-2035

CVSS v2.0 4.4 (Medium)
44% Progress
EPSS 0.04 % (11th)
0.04% Progress
Affected Products 1
Advisories 1

Race condition in hawtjni-runtime/src/main/java/org/fusesource/hawtjni/runtime/Library.java in HawtJNI before 1.8, when a custom library path is not specified, allows local users to execute arbitrary Java code by overwriting a temporary JAR file with a predictable name in /tmp.

Weaknesses
CWE-94
Improper Control of Generation of Code ('Code Injection')
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2013-08-28 23:55:04
(11 years ago)
Updated Date
2015-01-18 02:59:16
(9 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Redhat Hawtjni 1.7 and prior versions cpe:2.3:a:redhat:hawtjni <= 1.7
  Redhat Hawtjni 1.0 cpe:2.3:a:redhat:hawtjni:1.0
  Redhat Hawtjni 1.1 cpe:2.3:a:redhat:hawtjni:1.1
  Redhat Hawtjni 1.2 cpe:2.3:a:redhat:hawtjni:1.2
  Redhat Hawtjni 1.3 cpe:2.3:a:redhat:hawtjni:1.3
  Redhat Hawtjni 1.4 cpe:2.3:a:redhat:hawtjni:1.4
  Redhat Hawtjni 1.5 cpe:2.3:a:redhat:hawtjni:1.5
  Redhat Hawtjni 1.6 cpe:2.3:a:redhat:hawtjni:1.6
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...