MGASA-2021-0173

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 03 Apr 2021, 13:16
Last modified:16 Apr 2026, 04:25

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Apr 2021, 13:16
Published
Vulnerability first disclosed
16 Apr 2026, 04:25
Last Modified
Vulnerability information updated

Description

Updated ant packages fix security vulnerability Updated ant packages fix security vulnerability: As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process(CVE-2020-11979).

Affected Systems

  • mageiaant

    < 1.10.9-1.mga7

References (4)