Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-2217

Опубликовано: 27 июн. 2013
Источник: redhat
CVSS2: 1.9
EPSS Низкий

Описание

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

Отчет

This issue affects the version of python-suds as shipped with Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5python-sudsWill not fix
Red Hat Enterprise Linux 6python-sudsWill not fix
Red Hat Enterprise Linux 7python-sudsWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=978696python-suds: Insecure temporary directory use when initializing file-based URL cache

EPSS

Процентиль: 34%
0.00135
Низкий

1.9 Low

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

nvd
больше 12 лет назад

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

debian
больше 12 лет назад

cache.py in Suds 0.4, when tempdir is set to None, allows local users ...

suse-cvrf
больше 9 лет назад

Security update for python-suds-jurko

CVSS3: 6.2
github
больше 3 лет назад

Improper Link Resolution Before File Access in Suds

EPSS

Процентиль: 34%
0.00135
Низкий

1.9 Low

CVSS2