Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-6198

Опубликовано: 25 янв. 2018
Источник: nvd
CVSS3: 4.7
CVSS2: 3.3
EPSS Низкий

Описание

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:tats:w3m:*:*:*:*:*:*:*:*
Версия до 0.5.3 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*

EPSS

Процентиль: 40%
0.00179
Низкий

4.7 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 8 лет назад

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

CVSS3: 4.3
redhat
около 8 лет назад

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

CVSS3: 4.7
debian
около 8 лет назад

w3m through 0.5.3 does not properly handle temporary files when the ~/ ...

CVSS3: 4.7
github
больше 3 лет назад

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

suse-cvrf
почти 7 лет назад

Security update for w3m

EPSS

Процентиль: 40%
0.00179
Низкий

4.7 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-59