Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-1687

Опубликовано: 09 апр. 2008
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnu:m4:*:*:*:*:*:*:*:*
Версия до 1.4.10 (включая)

EPSS

Процентиль: 85%
0.02727
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
больше 17 лет назад

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

redhat
больше 17 лет назад

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

debian
больше 17 лет назад

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1. ...

github
больше 3 лет назад

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

EPSS

Процентиль: 85%
0.02727
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other