Derby
  1. Derby
  2. DERBY-4292

creation of FileInputStream in org.apache.derby.impl.tools.ij.Main not wrapped in privilege block which can cause problems running under SecurityManager

    Details

    • Type: Bug Bug
    • Status: Closed
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: 10.1.3.1, 10.2.2.0, 10.3.2.1, 10.4.2.0, 10.5.1.1, 10.6.1.0
    • Fix Version/s: 10.5.3.0, 10.6.1.0
    • Component/s: Tools
    • Labels:
      None
    • Urgency:
      Normal
    • Issue & fix info:
      High Value Fix, Newcomer, Repro attached
    • Bug behavior facts:
      Security

      Description

      org.apache.derby.impl.tools.ij.Main has this code where the call to FileInputStream is not wrapped in a privilege block:

      try {
      in1 = new FileInputStream(file);
      if (in1 != null)

      { in1 = new BufferedInputStream(in1, utilMain.BUFFEREDFILESIZE); in = langUtil.getNewInput(in1); }

      } catch (FileNotFoundException e) {
      if (Boolean.getBoolean("ij.searchClassPath"))

      { in = langUtil.getNewInput(util.getResourceAsStream(file)); }

      This can cause issues when running under SecurityManager

      1. derby4292.zip
        3 kB
        Kathey Marsden
      2. derby4292.zip
        5 kB
        Kathey Marsden
      3. DERBY-4292-Fix.patch
        2 kB
        Tiago R. Espinha
      4. DERBY-4292-Fix.patch
        2 kB
        Tiago R. Espinha
      5. DERBY-4292-Fix.patch
        1 kB
        Tiago R. Espinha
      6. DERBY-4292-ReproTest.patch
        7 kB
        Tiago R. Espinha
      7. DERBY-4292-ReproTest.patch
        7 kB
        Tiago R. Espinha
      8. DERBY-4292-ReproTest.patch
        3 kB
        Tiago R. Espinha
      9. run.out.debugall
        34 kB
        Kathey Marsden

        Activity

        Gavin made changes -
        Workflow jira [ 12466884 ] Default workflow, editable Closed status [ 12799379 ]
        Tiago R. Espinha made changes -
        Status Resolved [ 5 ] Closed [ 6 ]
        Kathey Marsden made changes -
        Status Open [ 1 ] Resolved [ 5 ]
        Fix Version/s 10.5.2.1 [ 12314117 ]
        Fix Version/s 10.6.0.0 [ 12313727 ]
        Resolution Fixed [ 1 ]
        Tiago R. Espinha made changes -
        Attachment DERBY-4292-ReproTest.patch [ 12412994 ]
        Kathey Marsden made changes -
        Attachment derby4292.zip [ 12412959 ]
        Tiago R. Espinha made changes -
        Attachment DERBY-4292-Fix.patch [ 12412934 ]
        Kathey Marsden made changes -
        Attachment run.out.debugall [ 12412916 ]
        Tiago R. Espinha made changes -
        Attachment DERBY-4292-Fix.patch [ 12412895 ]
        Attachment DERBY-4292-ReproTest.patch [ 12412896 ]
        Tiago R. Espinha made changes -
        Attachment DERBY-4292-Fix.patch [ 12412547 ]
        Attachment DERBY-4292-ReproTest.patch [ 12412548 ]
        Dag H. Wanvik made changes -
        Urgency Normal
        Issue & fix info [Newcomer, High Value Fix] [High Value Fix, Newcomer, Repro attached]
        Kathey Marsden made changes -
        Attachment derby4292.zip [ 12412337 ]
        Tiago R. Espinha made changes -
        Assignee Tiago R. Espinha [ espinha ]
        Dag H. Wanvik made changes -
        Issue & fix info [Newcomer] [High Value Fix, Newcomer]
        Dag H. Wanvik made changes -
        Issue & fix info [High Value Fix] [Newcomer]
        Dag H. Wanvik made changes -
        Field Original Value New Value
        Issue & fix info [High Value Fix]
        Kathey Marsden created issue -

          People

          • Assignee:
            Tiago R. Espinha
            Reporter:
            Kathey Marsden
          • Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved:

              Development