Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-18196

Опубликовано: 23 фев. 2018
Источник: nvd
CVSS3: 3.3
CVSS2: 2.1
EPSS Низкий

Описание

Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:leptonica:leptonica:1.74.4:*:*:*:*:*:*:*

EPSS

Процентиль: 18%
0.00056
Низкий

3.3 Low

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 3.3
ubuntu
почти 8 лет назад

Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.

CVSS3: 3.3
debian
почти 8 лет назад

Leptonica 1.74.4 constructs unintended pathnames (containing duplicate ...

CVSS3: 3.3
github
больше 3 лет назад

Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.

EPSS

Процентиль: 18%
0.00056
Низкий

3.3 Low

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-22