Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-6198

Опубликовано: 23 янв. 2018
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5w3mWill not fix
Red Hat Enterprise Linux 6w3mWill not fix
Red Hat Enterprise Linux 8w3mNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=1539127w3m: insecure temporary files creation when ~/.w3m is unwritable

EPSS

Процентиль: 32%
0.00395
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 8 лет назад

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

CVSS3: 4.7
nvd
больше 8 лет назад

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

CVSS3: 4.7
debian
больше 8 лет назад

w3m through 0.5.3 does not properly handle temporary files when the ~/ ...

CVSS3: 4.7
github
больше 4 лет назад

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

suse-cvrf
больше 7 лет назад

Security update for w3m

EPSS

Процентиль: 32%
0.00395
Низкий

4.3 Medium

CVSS3