CVE-2025-14307

NameCVE-2025-14307
DescriptionAn insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The createTempFile method fails to securely create temporary files, allowing attackers to exploit race conditions and potentially execute arbitrary code or overwrite critical files. This vulnerability can be exploited by manipulating the temporary file creation process, leading to potential unauthorized actions.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1122289

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
robocode (PTS)bullseye1.9.3.9-2vulnerable
bookworm1.9.3.9-3vulnerable
forky, sid, trixie1.9.3.9-4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
robocodesource(unstable)(unfixed)1122289

Notes

https://github.com/robo-code/robocode/pull/68
Fixed by: https://github.com/robo-code/robocode/commit/964b10f74064d04a3ea05a52b74ed86f485a13d5 (VER_1_9_5_6)
Fixed by: https://github.com/robo-code/robocode/commit/1638298ac872d7a92daf02de758f35f8012eae96 (VER_1_9_5_6)

Search for package or bug name: Reporting problems