Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3xgr-x5gv-64gh

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to write in a directory where files will be installed could create symbolic links to an arbitrary location and modify content, and possibly permissions to arbitrary files, which could be used for denial of service or possibly privilege escalation.

It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to write in a directory where files will be installed could create symbolic links to an arbitrary location and modify content, and possibly permissions to arbitrary files, which could be used for denial of service or possibly privilege escalation.

EPSS

Процентиль: 17%
0.00054
Низкий

7.8 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 8 лет назад

It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to write in a directory where files will be installed could create symbolic links to an arbitrary location and modify content, and possibly permissions to arbitrary files, which could be used for denial of service or possibly privilege escalation.

CVSS3: 7.3
redhat
больше 8 лет назад

It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to write in a directory where files will be installed could create symbolic links to an arbitrary location and modify content, and possibly permissions to arbitrary files, which could be used for denial of service or possibly privilege escalation.

CVSS3: 7.8
nvd
около 8 лет назад

It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to write in a directory where files will be installed could create symbolic links to an arbitrary location and modify content, and possibly permissions to arbitrary files, which could be used for denial of service or possibly privilege escalation.

CVSS3: 7.8
debian
около 8 лет назад

It was found that versions of rpm before 4.13.0.2 use temporary files ...

suse-cvrf
больше 7 лет назад

Security update for rpm

EPSS

Процентиль: 17%
0.00054
Низкий

7.8 High

CVSS3

Дефекты

CWE-59