VDB

GCVE-110-MAGEIA-2020-237

GCVE-110-MAGEIA-2020-237
Advisory Published
Vulnetix · Advisory published May 27, 2020
Updated ant packages fix security vulnerability: Apache Ant uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process (CVE-2020-1945). The ant package has been updated to version 1.10.8 to fix this issue and other bugs.

Affected Products

VendorProductVersionsPlatforms
Mageiaperl-URPM5.23-1.2.mga7 (unaffected), 0 (affected)
Mageiaant0 (affected), 0 (affected), 1.10.8-1.mga7 (unaffected), 1.10.8-1.mga7 (unaffected)

Browse GCVE Records

73,866 records in the GCVE database · Updated July 19, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›