Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-846g-25mr-v9p5

Опубликовано: 05 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

(1) installer/basedefs.py and (2) modules/ospluginutils.py in PackStack allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.

(1) installer/basedefs.py and (2) modules/ospluginutils.py in PackStack allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.

EPSS

Процентиль: 27%
0.00346
Низкий

8.8 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 8.8
redhat
больше 13 лет назад

A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This vulnerability allows the local user to overwrite arbitrary files on the system, potentially leading to system compromise or data corruption.

CVSS3: 8.8
nvd
больше 13 лет назад

A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This vulnerability allows the local user to overwrite arbitrary files on the system, potentially leading to system compromise or data corruption.

EPSS

Процентиль: 27%
0.00346
Низкий

8.8 High

CVSS3

Дефекты

CWE-59