OpenJDK insecure temporary File Processing Vulnerability (CVE-2015-3149)
OpenJDK insecure temporary File Processing Vulnerability (CVE-2015-3149)
Release date:
Updated on:
Affected Systems:
OpenJDK 8
OpenJDK
Description:
Bugtraq id: 75933
CVE (CAN) ID: CVE-2015-3149
OpenJDK is a cooperation Platform for open source implementation of Java Platform, Standard Edition and related projects.
OpenJDK is vulnerable to the temporary file processing issue of heat map data. This vulnerability allows local attackers to exploit this vulnerability to execute symbolic link attacks and overwrite any files in the affected application context.
<* Source: Tomas Hoger (thoger@redhat.com)
*>
Suggestion:
Vendor patch:
OpenJDK
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://openjdk.java.net/
Compile and install OpenJDK7 source code on CentOS 6.5
RHEL6.5 install OpenJDK1.7.0 + JBoss7.1.1 + Maven3.0.4
Install the official JDK under Fedora 20 to replace OpenJDK and configure environment variables.
Install Ubuntu OpenJDK + Tomcat 7
Upgrade Ubuntu 13.04 to Maven3.10 to support OpenJDK7
Compile and install OpenJDK 7 in Ubuntu 12.10
This article permanently updates the link address: