Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Mageia: 2020-0237 Critical: Apache Ant Task Injection Security Issue

mageia
Calendar Grey May 27, 2020
Dist Mageia Esm H88
The latest Ant updates for Mageia address a critical security vulnerability that exposes sensitive information in the default Java directory.
Updated ant packages fix security vulnerability: Apache Ant uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may th...

Summary

Updated ant packages fix security vulnerability:
Apache Ant uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process (CVE-2020-1945).
The ant package has been updated to version 1.10.8 to fix this issue and other bugs.

References

- https://bugs.mageia.org/show_bug.cgi?id=26618

- https://ant.apache.org/security.html

- https://ant.apache.org/antnews.html

- https://www.cve.org/CVERecord?id=CVE-2020-1945

Resolution

SRPMS

- 7/core/ant-1.10.8-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 27 May 2020
URL: https://advisories.mageia.org/MGASA-2020-0237.html
Type: security
CVE: CVE-2020-1945

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here