Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-13226

Опубликовано: 04 июл. 2019
Источник: nvd
CVSS3: 7
CVSS2: 6.9
EPSS Низкий

Описание

deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/ in the Helper::temporaryMountDevice() function to temporarily mount a file system as root. An unprivileged user can prepare a symlink at this location to have the file system mounted in an arbitrary location. By winning a race condition, the attacker can also enter the mount point, thereby preventing a subsequent unmount of the file system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:deepin:deepin-clone:*:*:*:*:*:*:*:*
Версия до 1.1.3 (исключая)
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

EPSS

Процентиль: 16%
0.0005
Низкий

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7
debian
больше 6 лет назад

deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/m ...

CVSS3: 7
github
больше 3 лет назад

deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to temporarily mount a file system as root. An unprivileged user can prepare a symlink at this location to have the file system mounted in an arbitrary location. By winning a race condition, the attacker can also enter the mount point, thereby preventing a subsequent unmount of the file system.

EPSS

Процентиль: 16%
0.0005
Низкий

7 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-59