Описание
cnlh nps vulnerable to file overwrite by local user
lib/install/install.go in cnlh nps prior to 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a local user.
Пакеты
Наименование
ehang.io/nps
go
Затронутые версииВерсия исправления
< 0.23.2
0.23.2
Связанные уязвимости
CVSS3: 5.5
nvd
больше 6 лет назад
lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a local user.