Описание
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Software Collections | nodejs010-npm | Affected |
Показывать по
10
Дополнительная информация
Статус:
Low
https://bugzilla.redhat.com/show_bug.cgi?id=983917npm: Insecure temporary directory generation
EPSS
Процентиль: 29%
0.00104
Низкий
1.9 Low
CVSS2
Связанные уязвимости
ubuntu
почти 12 лет назад
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.
nvd
почти 12 лет назад
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.
debian
почти 12 лет назад
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local us ...
EPSS
Процентиль: 29%
0.00104
Низкий
1.9 Low
CVSS2