Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q8qf-8pcx-vfw7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privileges via a symlink attack against the /tmp/testkeys file (related to t-testdata.h, t-setup.c, and t-cleanup.c). NOTE: this is applicable to persons who choose to engage in the "A number of self-test programs are included here for unit-testing the library" situation.

The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privileges via a symlink attack against the /tmp/testkeys file (related to t-testdata.h, t-setup.c, and t-cleanup.c). NOTE: this is applicable to persons who choose to engage in the "A number of self-test programs are included here for unit-testing the library" situation.

EPSS

Процентиль: 35%
0.00144
Низкий

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 5 лет назад

The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privileges via a symlink attack against the /tmp/testkeys file (related to t-testdata.h, t-setup.c, and t-cleanup.c). NOTE: this is applicable to persons who choose to engage in the "A number of self-test programs are included here for unit-testing the library" situation.

CVSS3: 7.8
nvd
около 5 лет назад

The test suite in libopendkim in OpenDKIM through 2.10.3 allows local users to gain privileges via a symlink attack against the /tmp/testkeys file (related to t-testdata.h, t-setup.c, and t-cleanup.c). NOTE: this is applicable to persons who choose to engage in the "A number of self-test programs are included here for unit-testing the library" situation.

CVSS3: 7.8
debian
около 5 лет назад

The test suite in libopendkim in OpenDKIM through 2.10.3 allows local ...

EPSS

Процентиль: 35%
0.00144
Низкий

Дефекты

CWE-59