Описание
Withdrawn Advisory: OnionShare Predictable Pathname
Withdrawn Advisory
This advisory has been withdrawn because the advisory concerns the repository https://github.com/onionshare/onionshare, which is not in a supported ecosystem. onionshare-cli is not affected by this issue.
Original Description
The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging, which might allow local users to overwrite files or obtain sensitive information by using this pathname.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-19960
- https://github.com/onionshare/onionshare/issues/837
- https://github.com/onionshare/onionshare/commit/4da5e15581a69509e7bfc6c4d0742052e0b61b24
- https://github.com/onionshare/onionshare/commit/aa5fdde6a4e4de7f113e01a3b446dcc14dcecb1a
- https://bugs.debian.org/915859
Пакеты
onionshare-cli
<= 1.3.1
Отсутствует
Связанные уязвимости
The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging, which might allow local users to overwrite files or obtain sensitive information by using this pathname.
The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging, which might allow local users to overwrite files or obtain sensitive information by using this pathname.
The debug_mode function in web/web.py in OnionShare through 1.3.1, whe ...