Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pv97-pjxj-gx6w

Опубликовано: 22 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if it has been created by a local adversary before Cadence started. The adversary can leverage this to create or overwrite files via a symlink attack. In some kernel configurations, code injection into the Wine registry is possible.

Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if it has been created by a local adversary before Cadence started. The adversary can leverage this to create or overwrite files via a symlink attack. In some kernel configurations, code injection into the Wine registry is possible.

EPSS

Процентиль: 16%
0.0005
Низкий

7.5 High

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if it has been created by a local adversary before Cadence started. The adversary can leverage this to create or overwrite files via a symlink attack. In some kernel configurations, code injection into the Wine registry is possible.

EPSS

Процентиль: 16%
0.0005
Низкий

7.5 High

CVSS3

Дефекты

CWE-668