Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j7g4-59wh-c9jc

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The register_application function in atk-adaptor/bridge.c in GNOME at-spi2-atk 2.5.2 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or truncate files via a symlink attack on a temporary socket file in /tmp/at-spi2.

The register_application function in atk-adaptor/bridge.c in GNOME at-spi2-atk 2.5.2 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or truncate files via a symlink attack on a temporary socket file in /tmp/at-spi2.

EPSS

Процентиль: 20%
0.00063
Низкий

Связанные уязвимости

ubuntu
больше 13 лет назад

The register_application function in atk-adaptor/bridge.c in GNOME at-spi2-atk 2.5.2 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or truncate files via a symlink attack on a temporary socket file in /tmp/at-spi2.

nvd
больше 13 лет назад

The register_application function in atk-adaptor/bridge.c in GNOME at-spi2-atk 2.5.2 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or truncate files via a symlink attack on a temporary socket file in /tmp/at-spi2.

debian
больше 13 лет назад

The register_application function in atk-adaptor/bridge.c in GNOME at- ...

EPSS

Процентиль: 20%
0.00063
Низкий