Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-62294

Опубликовано: 15 июл. 2026
Источник: debian
EPSS Низкий

Описание

Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause Flameshot to write PNG data through it, overwriting any file the victim user could write. This issue is fixed in version 14.0.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
flameshotfixed14.0.0-1package

Примечания

  • https://github.com/flameshot-org/flameshot/security/advisories/GHSA-fqqf-4rj8-c392

  • https://github.com/flameshot-org/flameshot/pull/4716

  • Fixed by: https://github.com/flameshot-org/flameshot/commit/936716b8d8b7052be461c3d5e2f88492b6eb3b96 (v14.0.0)

EPSS

Процентиль: 1%
0.00101
Низкий

Связанные уязвимости

ubuntu
22 дня назад

Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause Flameshot to write PNG data through it, overwriting any file the victim user could write. This issue is fixed in version 14.0.0.

nvd
22 дня назад

Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause Flameshot to write PNG data through it, overwriting any file the victim user could write. This issue is fixed in version 14.0.0.

EPSS

Процентиль: 1%
0.00101
Низкий