All errata/sisyphus/ALT-PU-2021-1999-2
ALT-PU-2021-1999-2

Package update scala in branch sisyphus

Version2.13.5-alt0.1jpp
Published2026-02-04
Max severityHIGH
Severity:

Closed issues (2)

CVE-2017-15288
HIGH7.8

The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local users to write to arbitrary class files and consequently gain privileges.

Published: 2017-11-15Modified: 2025-04-20
CVSS 2.0HIGH 7.2
CVSS:2.0/AV:L/AC:L/Au:N/C:C/I:C/A:C
CVSS 3.xHIGH 7.8
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
GHSA-qvxv-pmq9-4q7g
HIGH7.8

High severity vulnerability that affects org.scala-lang:scala-compiler

Published: 2018-10-19Modified: 2021-09-17
CVSS 3.xHIGH 7.8
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References