Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-85m4-23gq-w92v

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allows local users to cause a denial of service via a symlink attack on the bitrock_installer.log temporary file. NOTE: it is possible that this vulnerability is present in other products that use this installer.

A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allows local users to cause a denial of service via a symlink attack on the bitrock_installer.log temporary file. NOTE: it is possible that this vulnerability is present in other products that use this installer.

EPSS

Процентиль: 17%
0.00067
Низкий

Связанные уязвимости

nvd
больше 19 лет назад

A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allows local users to cause a denial of service via a symlink attack on the bitrock_installer.log temporary file. NOTE: it is possible that this vulnerability is present in other products that use this installer.

debian
больше 19 лет назад

A third-party installer generation tool, possibly BitRock InstallBuild ...

EPSS

Процентиль: 17%
0.00067
Низкий