Описание
everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.
Ссылки
- ExploitIssue Tracking
- Not ApplicableVendor Advisory
- Broken LinkThird Party AdvisoryVDB EntryVendor Advisory
- Broken LinkThird Party AdvisoryVDB EntryVendor Advisory
- Broken LinkVendor Advisory
- ExploitIssue Tracking
- Not ApplicableVendor Advisory
- Broken LinkThird Party AdvisoryVDB EntryVendor Advisory
- Broken LinkThird Party AdvisoryVDB EntryVendor Advisory
- Broken LinkVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.4.3 (включая)
cpe:2.3:a:everybuddy:everybuddy:*:*:*:*:*:*:*:*
EPSS
Процентиль: 42%
0.00201
Низкий
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-59
Связанные уязвимости
CVSS3: 5.5
github
почти 4 года назад
everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.
EPSS
Процентиль: 42%
0.00201
Низкий
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-59