Описание
pytest has vulnerable tmpdir handling
pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-71176
- https://github.com/pytest-dev/pytest/issues/13669
- https://github.com/pytest-dev/pytest/pull/14343
- https://github.com/pytest-dev/pytest/commit/95d8423bd24992deea5b9df32555fa1741679e2c
- https://github.com/pytest-dev/pytest/releases/tag/9.0.3
- https://www.openwall.com/lists/oss-security/2026/01/21/5
Пакеты
pytest
< 9.0.3
9.0.3
Связанные уязвимости
pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.
pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.
pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.
pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytes ...