CVE-2015-7810Time-of-check Time-of-use (TOCTOU) Race Condition in Libbluray

Severity
4.7MEDIUMNVD
EPSS
0.1%
top 70.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 22
Latest updateMay 24

Description

libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.0 | Impact: 3.6

Affected Packages5 packages

debiandebian/libbluray< libbluray 1:0.9.1-1 (bookworm)
NVDvideolan/libbluray< 0.8.0
Debianlibbluray/libbluray< 1:0.9.1-1+3
CVEListV5libbluray/libbluray1
apacheapache/tomcat

Also affects: Debian Linux 10.0, 8.0, 9.0, Fedora 17, 18, Enterprise Linux 7.0

🔴Vulnerability Details

2
GHSA
GHSA-3qpq-9423-wfmq: libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files2022-05-24
OSV
CVE-2015-7810: libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files2019-11-22

📋Vendor Advisories

3
Red Hat
(MountManager): TOCTOU race when expanding JAR files2015-02-06
Debian
CVE-2015-7810: libbluray - libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when ...2015
Apache
Apache tomcat: CVE-2014-7810

💬Community

1
Bugzilla
CVE-2015-7810 libbluray (MountManager): TOCTOU race when expanding JAR files2013-05-03