Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-55566

Опубликовано: 09 дек. 2024
Источник: debian

Описание

ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded RNG). The impact can be overwriting files or making ColPack graphing unavailable to other users.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
colpackunfixedpackage

Примечания

  • https://bugzilla.suse.com/show_bug.cgi?id=1225617

  • Negligible security impact with fs.protected_symlinks=1 being the standard in Debian

Связанные уязвимости

CVSS3: 6.6
ubuntu
около 1 года назад

ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded RNG). The impact can be overwriting files or making ColPack graphing unavailable to other users.

CVSS3: 6.6
nvd
около 1 года назад

ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded RNG). The impact can be overwriting files or making ColPack graphing unavailable to other users.

CVSS3: 6.6
github
около 1 года назад

ColPack 1.0.10 through 9a7293a has a predictable temporary file (located under /tmp with a name derived from an unseeded RNG). The impact can be overwriting files or making ColPack graphing unavailable to other users.