Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-4116

Опубликовано: 22 апр. 2014
Источник: debian

Описание

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
npmfixed1.3.10~dfsg-1package

Примечания

  • Upstream fix https://github.com/isaacs/npm/commit/f4d31693

  • https://github.com/isaacs/npm/issues/3635

Связанные уязвимости

ubuntu
почти 12 лет назад

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

redhat
больше 12 лет назад

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

nvd
почти 12 лет назад

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

github
больше 5 лет назад

Local Privilege Escalation in npm