Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2008-1687

Опубликовано: 02 апр. 2008
Источник: redhat
EPSS Низкий

Описание

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

Отчет

Red Hat does not consider this to be a security issue. After careful analysis of this issue the Red Hat Product Security has determined that this bug has no security impact outside of expected m4 behavior.

Дополнительная информация

https://bugzilla.redhat.com/show_bug.cgi?id=441876m4: unquoted output of maketemp and mkstemp

EPSS

Процентиль: 85%
0.02727
Низкий

Связанные уязвимости

ubuntu
больше 17 лет назад

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

nvd
больше 17 лет назад

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

debian
больше 17 лет назад

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1. ...

github
больше 3 лет назад

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

EPSS

Процентиль: 85%
0.02727
Низкий