CVE-2015-7810
published 2019-11-22CVE-2015-7810: libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
PriorityP418medium4.7CVSS 3.1
AVLACHPRLUINSUCNIHAN
EPSS
0.37%
28.8th percentile
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libbluray | < libbluray 1:0.9.1-1 (bookworm) | libbluray 1:0.9.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libbluray | libbluray | — | — |
| libbluray | libbluray | >= 0 < 1:0.9.1-1 | 1:0.9.1-1 |
| libbluray | libbluray | >= 0 < 1:0.9.1-1 | 1:0.9.1-1 |
| libbluray | libbluray | >= 0 < 1:0.9.1-1 | 1:0.9.1-1 |
| libbluray | libbluray | >= 0 < 1:0.9.1-1 | 1:0.9.1-1 |
| redhat | enterprise_linux | — | — |
| videolan | libbluray | < 0.8.0 | 0.8.0 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv4.7MEDIUM
vendor_apache5.0HIGH
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
(MountManager): TOCTOU race when expanding JAR files
vendor_redhat·2015-02-06·CVSS 4.7
CVE-2015-7810 [MEDIUM] CWE-367 (MountManager): TOCTOU race when expanding JAR files
(MountManager): TOCTOU race when expanding JAR files
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
Package: libbluray (Red Hat Enterprise Linux 7) - Affected
Debian
CVE-2015-7810: libbluray - libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when ...
vendor_debian·2015·CVSS 4.7
CVE-2015-7810 [MEDIUM] CVE-2015-7810: libbluray - libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when ...
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
Scope: local
bookworm: resolved (fixed in 1:0.9.1-1)
bullseye: resolved (fixed in 1:0.9.1-1)
forky: resolved (fixed in 1:0.9.1-1)
sid: resolved (fixed in 1:0.9.1-1)
trixie: resolved (fixed in 1:0.9.1-1)
Apache
Apache tomcat: CVE-2014-7810
vendor_apache·CVSS 5.0
CVE-2014-7810 [HIGH] Apache tomcat: CVE-2014-7810
Apache tomcat: CVE-2014-7810
Malicious web applications could use expression language to bypass the protections of a Security Manager as expressions were evaluated within a privileged code section. This was fixed in revisions 1644018 and 1645642 . This issue was identified by the Tomcat security team on 2 November 2014 and made public on 14 May 2015. Affects: 8.0.0-RC1 to 8.0.15 24 June 2014 Fixed in Apache Tomcat 8.0.9 Important: Request Smuggling
Severity: high
GHSA
GHSA-3qpq-9423-wfmq: libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
ghsa_unreviewed·2022-05-24
CVE-2015-7810 [LOW] GHSA-3qpq-9423-wfmq: libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
OSV
CVE-2015-7810: libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
osv·2019-11-22·CVSS 4.7
CVE-2015-7810 [MEDIUM] CVE-2015-7810: libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2015/10/12/7http://www.securityfocus.com/bid/72769https://access.redhat.com/security/cve/cve-2015-7810https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-7810https://security-tracker.debian.org/tracker/CVE-2015-7810http://www.openwall.com/lists/oss-security/2015/10/12/7http://www.securityfocus.com/bid/72769https://access.redhat.com/security/cve/cve-2015-7810https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-7810https://security-tracker.debian.org/tracker/CVE-2015-7810
2019-11-22
Published