Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 7: 2021-0173 Critical Advisory on Apache Ant Code Injection

mageia
Calendar Grey April 3, 2021
Dist Mageia Esm H88
Latest updates for Ant packages have been released to address a vulnerability permitting code execution due to a permissions error. Refer to the Mageia advisory for further information.
Updated ant packages fix security vulnerability: As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current u...

Summary

Updated ant packages fix security vulnerability:
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process(CVE-2020-11979).

References

- https://bugs.mageia.org/show_bug.cgi?id=27386

- https://www.openwall.com/lists/oss-security/2020/09/30/6

- https://ant.apache.org/security.html

- https://www.cve.org/CVERecord?id=CVE-2020-11979

Resolution

SRPMS

- 7/core/ant-1.10.9-1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 03 Apr 2021
URL: https://advisories.mageia.org/MGASA-2021-0173.html
Type: security
CVE: CVE-2020-11979

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here