Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gpc9-w434-fvwx

Опубликовано: 05 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.1

Описание

In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local attacker who can create files in advance with these names. This affects, for example, plot2d.

In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local attacker who can create files in advance with these names. This affects, for example, plot2d.

EPSS

Процентиль: 4%
0.0002
Низкий

5.1 Medium

CVSS3

Дефекты

CWE-377

Связанные уязвимости

CVSS3: 5.1
ubuntu
почти 2 года назад

In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local attacker who can create files in advance with these names. This affects, for example, plot2d.

CVSS3: 5.1
nvd
почти 2 года назад

In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local attacker who can create files in advance with these names. This affects, for example, plot2d.

CVSS3: 5.1
debian
почти 2 года назад

In Maxima through 5.47.0 before 51704c, the plotting facilities make u ...

EPSS

Процентиль: 4%
0.0002
Низкий

5.1 Medium

CVSS3

Дефекты

CWE-377