Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7wr8-6fw9-mw29

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/ in the Helper::temporaryMountDevice() function to temporarily mount a file system as root. An unprivileged user can prepare a symlink at this location to have the file system mounted in an arbitrary location. By winning a race condition, the attacker can also enter the mount point, thereby preventing a subsequent unmount of the file system.

deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/ in the Helper::temporaryMountDevice() function to temporarily mount a file system as root. An unprivileged user can prepare a symlink at this location to have the file system mounted in an arbitrary location. By winning a race condition, the attacker can also enter the mount point, thereby preventing a subsequent unmount of the file system.

EPSS

Процентиль: 16%
0.0005
Низкий

7 High

CVSS3

Дефекты

CWE-362
CWE-59

Связанные уязвимости

CVSS3: 7
nvd
больше 6 лет назад

deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to temporarily mount a file system as root. An unprivileged user can prepare a symlink at this location to have the file system mounted in an arbitrary location. By winning a race condition, the attacker can also enter the mount point, thereby preventing a subsequent unmount of the file system.

CVSS3: 7
debian
больше 6 лет назад

deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/m ...

EPSS

Процентиль: 16%
0.0005
Низкий

7 High

CVSS3

Дефекты

CWE-362
CWE-59