Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia 7: MGASA-2021-0021 Critical: Guava Temp Directory Risk

mageia
Calendar Grey January 10, 2021
Dist Mageia Esm H88
An issue in Guava exposes temporary directories. Information on remediation and impacted versions is included.
A temp directory creation vulnerability exist in Guava versions prior to 30.0 allowing an attacker with access to the machine to potentially access data in a temporary directory cr...

Summary

A temp directory creation vulnerability exist in Guava versions prior to 30.0 allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava com.google.common.io.Files.createTempDir(). The permissions granted to the directory created default to the standard unix-like /tmp ones, leaving the files open (CVE-2020-8908).

References

- https://bugs.mageia.org/show_bug.cgi?id=27965

- https://bugzilla.redhat.com/show_bug.cgi?id=1906919

- https://www.cve.org/CVERecord?id=CVE-2020-8908

Resolution

SRPMS

- 7/core/guava-25.0-2.1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 10 Jan 2021
URL: https://advisories.mageia.org/MGASA-2021-0021.html
Type: security
CVE: CVE-2020-8908

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here