Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q9w8-9j2h-5cw2

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse program.

Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse program.

EPSS

Процентиль: 13%
0.00042
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse program.

CVSS3: 5.5
nvd
больше 7 лет назад

Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse program.

CVSS3: 5.5
debian
больше 7 лет назад

Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary f ...

EPSS

Процентиль: 13%
0.00042
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-269