Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1213365 - (CVE-2015-3149) CVE-2015-3149 OpenJDK8: insecure hsperfdata temporary file handling, CVE-2015-0383 regression (Hotspot)
CVE-2015-3149 OpenJDK8: insecure hsperfdata temporary file handling, CVE-2015...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20140420,reported=2...
: Security
Depends On: 1213381
Blocks: 1235167
  Show dependency treegraph
 
Reported: 2015-04-20 07:31 EDT by Tomas Hoger
Modified: 2015-10-14 09:37 EDT (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-07-15 09:17:58 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:1228 normal SHIPPED_LIVE Important: java-1.8.0-openjdk security update 2015-07-15 12:37:01 EDT

  None (edit)
Description Tomas Hoger 2015-04-20 07:31:13 EDT
It was discovered that the java-1.8.0-openjdk packages for Red Hat Enterprise Linux released via RHSA-2015:0809 (https://rhn.redhat.com/errata/RHSA-2015-0809.html) regressed the fix for the CVE-2015-0383 (bug 1123870) issue - "OpenJDK: insecure hsperfdata temporary file handling (Hotspot, 8050807)".  This regression makes it possible to exploit the original issue and allow local attacker to make other users of OpenJDK 8 packages to overwrite arbitrary file via a symlink attack.  Refer to bug 1123870 for technical details.
Comment 2 Tomas Hoger 2015-04-20 07:35:11 EDT
This issue also affected java-1.8.0-openjdk-1.8.0.45-31.b13 Fedora packages (currently only in updates-testing repository).
Comment 4 Tomas Hoger 2015-04-20 08:45:20 EDT
Created java-1.8.0-openjdk tracking bugs for this issue:

Affects: fedora-all [bug 1213381]
Comment 5 errata-xmlrpc 2015-07-15 08:37:25 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6
  Red Hat Enterprise Linux 7

Via RHSA-2015:1228 https://rhn.redhat.com/errata/RHSA-2015-1228.html

Note You need to log in before you can comment on or make changes to this bug.