Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wc62-h53h-g8qf

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

EPSS

Процентиль: 48%
0.00655
Низкий

7.1 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 7 лет назад

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

CVSS3: 6.5
redhat
больше 7 лет назад

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

CVSS3: 7.1
nvd
около 7 лет назад

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

CVSS3: 7.1
debian
около 7 лет назад

libqb before 1.0.5 allows local users to overwrite arbitrary files via ...

suse-cvrf
около 7 лет назад

Security update for libqb

EPSS

Процентиль: 48%
0.00655
Низкий

7.1 High

CVSS3

Дефекты

CWE-59