Updated guava packages fix security vulnerability
Publication date: 10 Jan 2021Modification date: 10 Jan 2021
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-8908
Description
A temp directory creation vulnerability exist in Guava versions prior to 30.0 allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava com.google.common.io.Files.createTempDir(). The permissions granted to the directory created default to the standard unix-like /tmp ones, leaving the files open (CVE-2020-8908).
References
SRPMS
7/core
- guava-25.0-2.1.mga7