First published: Mon Jun 01 2020(Updated: )
It was discovered that Apache Ant created temporary files with insecure permissions. An attacker could use this vulnerability to read sensitive information leaked into /tmp, or potentially inject malicious code into a project that is built with Apache Ant.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/ant | <1.10.6-1ubuntu0.1 | 1.10.6-1ubuntu0.1 |
=19.10 | ||
All of | ||
ubuntu/ant-doc | <1.10.6-1ubuntu0.1 | 1.10.6-1ubuntu0.1 |
=19.10 | ||
All of | ||
ubuntu/ant-optional | <1.10.6-1ubuntu0.1 | 1.10.6-1ubuntu0.1 |
=19.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of USN-4380-1 is CVE-2020-1945.
The affected software for USN-4380-1 is Apache Ant.
The potential impact of the vulnerability in USN-4380-1 is the ability for an attacker to read sensitive information leaked into /tmp or potentially inject malicious code into a project built with Apache Ant.
To fix USN-4380-1, update Apache Ant to version 1.10.6-1ubuntu0.1 or higher.
You can find more information about USN-4380-1 at the following references: [Link 1](https://ubuntu.com/security/CVE-2020-1945), [Link 2](https://ubuntu.com/security/notices/USN-4874-1), [Link 3](https://launchpad.net/ubuntu/+source/ant/1.10.6-1ubuntu0.1)