VDB
RHSA-2013%3A1784
RHSA-2013%3A1784
PUBLISHED
CVSS 3.299999952316284 LOW
The HawtJNI Library class wrote native libraries to a predictable file name in /tmp when the native libraries were bundled in a JAR file, and no custom library path was specified. A local attacker could overwrite these native libraries with malicious versions during the window between when HawtJNI writes them and when they are executed.
Risk Scores
CVSS 2.0
3.299999952316284
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 6.2 |
Timeline
- Dec 4, 2013 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2013:1784 advisory
- https://access.redhat.com/security/updates/classification/#low advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=distributions advisory
- https://access.redhat.com/site/documentation/en-US/JBoss_Enterprise_Application_Platform/6.2/html/6.2.0_Release_Notes/index.html advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=958618 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=969924 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2013/rhsa-2013_1784.json advisory
- https://access.redhat.com/security/cve/CVE-2013-2035 advisory
- https://www.cve.org/CVERecord?id=CVE-2013-2035 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-2035 advisory
- https://access.redhat.com/security/cve/CVE-2013-2133 advisory
- https://www.cve.org/CVERecord?id=CVE-2013-2133 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-2133 advisory