OSV 1.4.0 · github-reviewed · 修改于 2022-05-04 03:31
发布时间
2022-02-10 06:25
GitHub 审查时间
2021-04-07 06:32
NVD 发布时间
2021-01-12 00:15
源文件
advisories/github-reviewed/2022/02/GHSA-ppc3-fpvh-7396/GHSA-ppc3-fpvh-7396.json
There exists a race condition between the deletion of the temporary file and the creation of the temporary directory in webkit subproject of HTML/Java API version 1.7. A similar vulnerability has recently been disclosed in other Java projects and the fix in HTML/Java API version 1.7.1 follows theirs: To avoid local privilege escalation version 1.7.1 creates the temporary directory atomically without dealing with the temporary file.