MGASA-2020-0403

Source
https://advisories.mageia.org/MGASA-2020-0403.html
Import Source
https://advisories.mageia.org/MGASA-2020-0403.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2020-0403
Related
Published
2020-11-08T14:14:27Z
Modified
2020-11-08T13:38:28Z
Summary
Updated junit packages fix a security vulnerability
Details

It was discovered that junit contained a local information disclosure vulnerability. On Unix like systems, the system's temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by default, readable by other users on that same system. This vulnerability does not allow other users to overwrite the contents of these directories or files. This is purely an information disclosure vulnerability (CVE-2020-15250).

References
Credits

Affected packages

Mageia:7 / junit

Package

Name
junit
Purl
pkg:rpm/mageia/junit?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12-7.1.mga7

Ecosystem specific

{
    "section": "core"
}