CVE-2015-0383

Public on 2015-01-21
Modified on 2015-07-22
Description
Multiple insecure temporary file use issues were found in the way the Hotspot component in OpenJDK created performance statistics and error log files. A local attacker could possibly make a victim using OpenJDK overwrite arbitrary files using a symlink attack.
Severity
Low severity
Low
CVSS v3 Base Score
3.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 java-1.6.0-openjdk 2015-02-11 ALAS-2015-480 Fixed
Amazon Linux 1 java-1.7.0-openjdk 2015-01-22 ALAS-2015-471 Fixed
Amazon Linux 1 java-1.8.0-openjdk 2015-01-22 ALAS-2015-472 Fixed
Amazon Linux 1 java-1.8.0-openjdk 2015-07-22 ALAS-2015-571 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv2 3.3 AV:L/AC:M/Au:N/C:N/I:P/A:P
NVD CVSSv2 5.4 AV:L/AC:M/Au:N/C:N/I:P/A:C