Race condition in hawtjni-runtime/src/main/java/org/fusesource/hawtjni/runtime/Library.java in HawtJNI before 1.8, when a custom library path is not specified, allows local users to execute arbitrary Java code by overwriting a temporary JAR file with a predictable name in /tmp.
2013-08-28T23:55:04.823
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.4 (MEDIUM)
AV:L/AC:M/Au:N/C:P/I:P/A:P
3.4
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | hawtjni | ≤ 1.7 | Yes |
Application | redhat | hawtjni | 1.0 | Yes |
Application | redhat | hawtjni | 1.1 | Yes |
Application | redhat | hawtjni | 1.2 | Yes |
Application | redhat | hawtjni | 1.3 | Yes |
Application | redhat | hawtjni | 1.4 | Yes |
Application | redhat | hawtjni | 1.5 | Yes |
Application | redhat | hawtjni | 1.6 | Yes |