Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-847x-vxjh-whpv

Опубликовано: 07 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.

EPSS

Процентиль: 2%
0.00113
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 5.3
ubuntu
7 дней назад

(A flaw was found in GLib2. When g_file_replace() is used with G_FILE_C ...)

CVSS3: 5.3
redhat
9 дней назад

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.

CVSS3: 5.3
nvd
9 дней назад

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.

CVSS3: 5.3
debian
9 дней назад

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_C ...

EPSS

Процентиль: 2%
0.00113
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-59