{"id":"MGASA-2014-0461","summary":"Updated hawtjni packages fix security vulnerability","details":"The HawtJNI Library class wrote native libraries to a predictable file name\nin /tmp/ when the native libraries were bundled in a JAR file, and no\ncustom library path was specified. A local attacker could overwrite these\nnative libraries with malicious versions during the window between when\nHawtJNI writes them and when they are executed (CVE-2013-2035).\n","modified":"2026-04-16T01:46:50.791960160Z","published":"2014-11-21T12:44:16Z","upstream":["CVE-2013-2035"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2014-0461.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=12934"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2014-0245.html"}],"affected":[{"package":{"name":"hawtjni","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/hawtjni?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2014-0461.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}