Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-43783

Опубликовано: 22 сент. 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if it has been created by a local adversary before Cadence started. The adversary can leverage this to create or overwrite files via a symlink attack. In some kernel configurations, code injection into the Wine registry is possible.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:falktx:cadence:*:*:*:*:*:*:*:*
Версия до 0.9.2 (включая)

EPSS

Процентиль: 16%
0.0005
Низкий

7.5 High

CVSS3

Дефекты

CWE-668

Связанные уязвимости

CVSS3: 7.5
github
больше 2 лет назад

Cadence through 0.9.2 2023-08-21 uses an Insecure /tmp/cadence-wineasio.reg Temporary File. The filename is used even if it has been created by a local adversary before Cadence started. The adversary can leverage this to create or overwrite files via a symlink attack. In some kernel configurations, code injection into the Wine registry is possible.

EPSS

Процентиль: 16%
0.0005
Низкий

7.5 High

CVSS3

Дефекты

CWE-668