Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-29465

Опубликовано: 06 апр. 2023
Источник: debian
EPSS Низкий

Описание

SageMath FlintQS 1.0 relies on pathnames under TMPDIR (typically world-writable), which (for example) allows a local user to overwrite files with the privileges of a different user (who is running FlintQS).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
flintqsunfixedpackage

Примечания

  • https://github.com/sagemath/FlintQS/issues/3

  • https://github.com/sagemath/sage/pull/35419

  • Neutralised by kernel hardening

EPSS

Процентиль: 11%
0.00038
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 3 года назад

SageMath FlintQS 1.0 relies on pathnames under TMPDIR (typically world-writable), which (for example) allows a local user to overwrite files with the privileges of a different user (who is running FlintQS).

CVSS3: 5.5
nvd
почти 3 года назад

SageMath FlintQS 1.0 relies on pathnames under TMPDIR (typically world-writable), which (for example) allows a local user to overwrite files with the privileges of a different user (who is running FlintQS).

CVSS3: 5.5
github
почти 3 года назад

SageMath FlintQS 1.0 relies on pathnames under TMPDIR (typically world-writable), which (for example) allows a local user to overwrite files with the privileges of a different user (who is running FlintQS).

EPSS

Процентиль: 11%
0.00038
Низкий