Back

HIGH

scala: Privilege escalation in Scala compilation daemon

Published Nov 15, 2017

Description

The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local users to write to arbitrary class files and consequently gain privileges.

Affected products

Remediation

Red Hat mitigation

1. Use "scala -nocompdaemon MyScript.scala" rather than "scala MyScript.scala" to disable the implicit startup and use of the daemon. 2. Avoid explicitly starting fsc. This text is borrowed from the upstream security advisory.

Metrics

References (38)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 15, 2017
Updated Aug 5, 2024
Reserved Oct 12, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 13, 2017
GHSA-QVXV-PMQ9-4Q7G