Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gvjc-4rfj-mxxj

Опубликовано: 13 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7

Описание

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.

EPSS

Процентиль: 4%
0.0014
Низкий

7 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7
redhat
3 месяца назад

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.

CVSS3: 7
nvd
около 2 месяцев назад

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.

EPSS

Процентиль: 4%
0.0014
Низкий

7 High

CVSS3

Дефекты

CWE-59