Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-6198

Опубликовано: 25 янв. 2018
Источник: debian
EPSS Низкий

Описание

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
w3mfixed0.5.3-36package
w3mfixed0.5.3-34+deb9u1stretchpackage

Примечания

  • https://github.com/tats/w3m/commit/18dcbadf2771cdb0c18509b14e4e73505b242753

  • Neutralised by kernel hardening

EPSS

Процентиль: 33%
0.00395
Низкий

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 8 лет назад

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

CVSS3: 4.3
redhat
больше 8 лет назад

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

CVSS3: 4.7
nvd
больше 8 лет назад

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

CVSS3: 4.7
github
больше 4 лет назад

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

suse-cvrf
больше 7 лет назад

Security update for w3m

EPSS

Процентиль: 33%
0.00395
Низкий