Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-6198

Опубликовано: 23 янв. 2018
Источник: redhat
CVSS3: 4.3

Описание

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5w3mWill not fix
Red Hat Enterprise Linux 6w3mWill not fix
Red Hat Enterprise Linux 8w3mNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=1539127w3m: insecure temporary files creation when ~/.w3m is unwritable

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 8 лет назад

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

CVSS3: 4.7
nvd
около 8 лет назад

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

CVSS3: 4.7
debian
около 8 лет назад

w3m through 0.5.3 does not properly handle temporary files when the ~/ ...

CVSS3: 4.7
github
больше 3 лет назад

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

suse-cvrf
почти 7 лет назад

Security update for w3m

4.3 Medium

CVSS3