Описание
Hub Package Arbitrary File Overwrite
The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2014-0177
- https://github.com/github/hub/commit/016ec99d25b1cb83cb4367e541177aa431beb600
- https://github.com/mislav/hub/commit/016ec99d25b1cb83cb4367e541177aa431beb600
- https://github.com/mislav/hub/releases/tag/v1.12.1
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/hub/CVE-2014-0177.yml
Пакеты
Наименование
github.com/github/hub
go
Затронутые версииВерсия исправления
< 1.12.1
1.12.1
Наименование
hub
rubygems
Затронутые версииВерсия исправления
< 1.12.1
1.12.1
Связанные уязвимости
ubuntu
больше 11 лет назад
The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file.
nvd
больше 11 лет назад
The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file.