VDB

CVE-2020-17534

CVE-2020-17534 PUBLISHED

There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in `webkit` subproject of HTML/Java API version 1.7. A similar vulnerability has recently been disclosed in other Java projects and the fix in HTML/Java API version 1.7.1 follows theirs: To avoid local privilege escalation version 1.7.1 creates the temporary directory atomically without dealing with the temporary file: https://github.com/apache/netbeans-html4j/commit/fa70e507e5555e1adb4f6518479fc408a7abd0e6

EPSS 0.07% · 21.2th percentile

Risk Scores

EPSS Score
0.07%
21.2th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSnetbeans0, 10.0-3ubuntu3
Ubuntu:18.04:LTSnetbeans*, *, 0
Ubuntu:25.10netbeans0, 12.1-3
Ubuntu:16.04:LTSnetbeans0, 8.0.2+dfsg1-5, 8.1+dfsg1-1
Ubuntu:22.04:LTSnetbeans12.1-3, 0
Ubuntu:24.04:LTSnetbeans0, 12.1-3

Timeline

  • Jan 11, 2021 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›