Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wcxv-32f4-xr5v

Опубликовано: 02 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.

EPSS

Процентиль: 33%
0.00397
Низкий

3.7 Low

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 3.7
ubuntu
11 месяцев назад

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.

CVSS3: 3.7
redhat
около 1 года назад

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.

CVSS3: 3.7
nvd
11 месяцев назад

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.

CVSS3: 3.7
msrc
11 месяцев назад

Glib: buffer under-read on glib through glib/gfileutils.c via get_tmp_file()

CVSS3: 3.7
debian
11 месяцев назад

A flaw was found in glib. An integer overflow during temporary file cr ...

EPSS

Процентиль: 33%
0.00397
Низкий

3.7 Low

CVSS3

Дефекты

CWE-22