Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r798-gf85-6mc8

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.

mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.

EPSS

Процентиль: 26%
0.00086
Низкий

7.1 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.1
nvd
почти 22 года назад

mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.

CVSS3: 7.1
debian
почти 22 года назад

mod_gzip 1.3.26.1a and earlier, and possibly later official versions, ...

EPSS

Процентиль: 26%
0.00086
Низкий

7.1 High

CVSS3

Дефекты

CWE-59