Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevation by local users.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://bugs.eclipse.org/bugs/show_bug.cgi?id=549191 | vendor advisory |