Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-1687

Опубликовано: 09 апр. 2008
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnu:m4:*:*:*:*:*:*:*:*
Версия до 1.4.10 (включая)

EPSS

Процентиль: 86%
0.02727
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
почти 18 лет назад

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

redhat
почти 18 лет назад

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

debian
почти 18 лет назад

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1. ...

github
почти 4 года назад

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

EPSS

Процентиль: 86%
0.02727
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other