PT-2013-3515 · Hawtjni · Hawtjni

Dfjo

·

Published

2013-08-28

·

Updated

2022-05-17

·

CVE-2013-2035

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions HawtJNI versions prior to 1.8
Description A race condition exists in the HawtJNI library, specifically in the Library.java file. This issue allows local users to execute arbitrary Java code by overwriting a temporary JAR file with a predictable name in the /tmp directory, but only when a custom library path is not specified.
Recommendations For HawtJNI versions prior to 1.8, update to version 1.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the temporary directory /tmp to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2035
GHSA-49J7-QGHP-5WJ8
MGASA-2014-0461
RHSA-2013:1785
RHSA-2013:1786
RHSA-2014:0245
RHSA-2014:0254

Affected Products

Hawtjni