Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m7cp-w3xh-qr3p

Опубликовано: 16 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the information in that file.

In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the information in that file.

EPSS

Процентиль: 15%
0.00048
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 6.3
nvd
почти 3 года назад

In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the information in that file.

CVSS3: 6.3
debian
почти 3 года назад

In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. ...

EPSS

Процентиль: 15%
0.00048
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-59