UBUNTU-CVE-2020-17534

Source
https://ubuntu.com/security/CVE-2020-17534
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-17534.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2020-17534
Related
Published
2021-01-11T16:15:00Z
Modified
2024-10-15T14:07:34Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in webkit subproject of HTML/Java API version 1.7. A similar vulnerability has recently been disclosed in other Java projects and the fix in HTML/Java API version 1.7.1 follows theirs: To avoid local privilege escalation version 1.7.1 creates the temporary directory atomically without dealing with the temporary file: https://github.com/apache/netbeans-html4j/commit/fa70e507e5555e1adb4f6518479fc408a7abd0e6

References

Affected packages

Ubuntu:Pro:16.04:LTS / netbeans

Package

Name
netbeans
Purl
pkg:deb/ubuntu/netbeans?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8.*

8.0.2+dfsg1-4
8.0.2+dfsg1-5
8.1+dfsg1-1
8.1+dfsg2-1
8.1+dfsg2-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / netbeans

Package

Name
netbeans
Purl
pkg:deb/ubuntu/netbeans?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8.*

8.1+dfsg3-4

10.*

10.0-3~18.04.1ubuntu1
10.0-3ubuntu2~18.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / netbeans

Package

Name
netbeans
Purl
pkg:deb/ubuntu/netbeans?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

10.*

10.0-3ubuntu3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / netbeans

Package

Name
netbeans
Purl
pkg:deb/ubuntu/netbeans?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

12.*

12.1-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / netbeans

Package

Name
netbeans
Purl
pkg:deb/ubuntu/netbeans?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

12.*

12.1-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / netbeans

Package

Name
netbeans
Purl
pkg:deb/ubuntu/netbeans?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

12.*

12.1-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}