Описание
pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- Third Party Advisory
- Vendor Advisory
- ExploitIssue TrackingThird Party Advisory
- Third Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.15 (исключая)
cpe:2.3:a:pyro_project:pyro:*:*:*:*:*:*:*:*
EPSS
Процентиль: 80%
0.02188
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-59
Связанные уязвимости
CVSS3: 7.5
ubuntu
почти 8 лет назад
pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.
CVSS3: 7.5
debian
почти 8 лет назад
pyro before 3.15 unsafely handles pid files in temporary directory loc ...
CVSS3: 7.5
github
почти 8 лет назад
Pyro mishandles pid files in temporary directory locations and opening the pid file as root
EPSS
Процентиль: 80%
0.02188
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-59