CVE-2013-2035

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
28/08/2013
Last modified:
11/04/2025

Description

Race condition in hawtjni-runtime/src/main/java/org/fusesource/hawtjni/runtime/Library.java in HawtJNI before 1.8, when a custom library path is not specified, allows local users to execute arbitrary Java code by overwriting a temporary JAR file with a predictable name in /tmp.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:hawtjni:*:*:*:*:*:*:*:* 1.7 (including)
cpe:2.3:a:redhat:hawtjni:1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hawtjni:1.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hawtjni:1.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hawtjni:1.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hawtjni:1.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hawtjni:1.5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:hawtjni:1.6:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools