Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2008-1687

Опубликовано: 09 апр. 2008
Источник: debian
EPSS Низкий

Описание

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
m4unfixedpackage

Примечания

  • This is more a generic bug and not a security issue: the random output would

  • need to match the name of an existing macro

EPSS

Процентиль: 85%
0.02727
Низкий

Связанные уязвимости

ubuntu
больше 17 лет назад

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

redhat
больше 17 лет назад

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

nvd
больше 17 лет назад

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

github
больше 3 лет назад

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

EPSS

Процентиль: 85%
0.02727
Низкий