Opened 16 months ago

Closed 16 months ago

Last modified 14 months ago

#13533 closed enhancement (fixed)

apache-ant-1.10.8

Reported by: Bruce Dubbs Owned by: thomas
Priority: normal Milestone: 10.0
Component: BOOK Version: SVN
Severity: normal Keywords:
Cc:

Description

New point version.

Change History (5)

comment:1 by Douglas R. Reno, 16 months ago

This fixes CVE-2020-1945

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

CVE-2020-1945: Apache Ant insecure temporary file vulnerability

Severity: Medium

Vendor:
The Apache Software Foundation

Versions Affected:
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7

Description:

Apache Ant uses the default temporary directory identified by the Java
system property java.io.tmpdir for several tasks and may thus leak
sensitive information. The fixcrlf and replaceregexp tasks also copy
files from the temporary directory back into the build tree allowing an
attacker to inject modified source files into the build process.

Mitigation:

Ant users of versions 1.1 to 1.9.14 and 1.10.0 to 1.10.7 should set the
java.io.tmpdir system property to point to a directory only readable and
writable by the current user prior to running Ant.

Users of versions 1.9.15 and 1.10.8 can use the Ant property ant.tmpfile
instead. Users of Ant 1.10.8 can rely on Ant protecting the temporary
files if the underlying filesystem allows it, but we still recommend
using a private temporary directory instead.

Credit:
This issue was discovered by Mike Salvatore of the Ubuntu Security Team.

References:
https://ant.apache.org/security.html
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iEYEARECAAYFAl68InYACgkQohFa4V9ri3JMuwCeJCxfVbb0FX7oVgzUpskGH28u
ZIYAoLDKeuyh585wmuiCySIj5EW4hYch
=KIJP
-----END PGP SIGNATURE-----

comment:2 by thomas, 16 months ago

Owner: changed from blfs-book to thomas
Status: newassigned

comment:3 by thomas, 16 months ago

Resolution: fixed
Status: assignedclosed

Fixed in r23138

comment:4 by Bruce Dubbs, 14 months ago

Milestone: 9.210,0

Milestone renamed

comment:5 by Bruce Dubbs, 14 months ago

Milestone: 10,010.0

Milestone renamed

Note: See TracTickets for help on using tickets.