Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-20197

Опубликовано: 26 мар. 2021
Источник: nvd
CVSS3: 6.3
CVSS2: 3.3
EPSS Низкий

Описание

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*
Версия до 2.35 (включая)
Конфигурация 2
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
cpe:2.3:o:broadcom:brocade_fabric_operating_system_firmware:-:*:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.00193
Низкий

6.3 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-59
CWE-59

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 4 лет назад

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

CVSS3: 4.2
redhat
почти 5 лет назад

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

CVSS3: 6.3
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 6.3
debian
больше 4 лет назад

There is an open race window when writing output in the following util ...

CVSS3: 6.3
github
больше 3 лет назад

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink.

EPSS

Процентиль: 41%
0.00193
Низкий

6.3 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-59
CWE-59