PT-2017-13970 · Scala+1 · Scala+1

Published

2017-11-15

·

Updated

2021-06-15

·

CVE-2017-15288

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Scala versions 2.10.0 through 2.10.6 Scala versions 2.11.0 through 2.11.11 Scala versions 2.12.0 through 2.12.3
Description The compilation daemon in Scala uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port. This allows local users to write to arbitrary class files and gain privileges.
Recommendations For Scala versions 2.10.0 through 2.10.6, update to version 2.10.7 or later. For Scala versions 2.11.0 through 2.11.11, update to version 2.11.12 or later. For Scala versions 2.12.0 through 2.12.3, update to version 2.12.4 or later.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1999
CVE-2017-15288
GHSA-QVXV-PMQ9-4Q7G

Affected Products

Alt Linux
Scala