Опубликовано: 07 нояб. 2019
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5.5
CVSS3: 6.5
Описание
Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID.tmp), enabling attackers to overwrite an arbitrary file via a symlink attack.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | |
| hardy | DNE | |
| lucid | ignored | end of life |
| maverick | not-affected | 0.26-2 |
| natty | not-affected | |
| oneiric | not-affected | |
| precise | not-affected | |
| quantal | not-affected | |
| raring | not-affected | |
| saucy | not-affected |
Показывать по
10
Ссылки на источники
EPSS
Процентиль: 75%
0.01702
Низкий
5.5 Medium
CVSS2
6.5 Medium
CVSS3
Связанные уязвимости
CVSS3: 6.5
nvd
почти 7 лет назад
Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID.tmp), enabling attackers to overwrite an arbitrary file via a symlink attack.
CVSS3: 6.5
debian
почти 7 лет назад
Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID. ...
github
больше 4 лет назад
Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID.tmp), enabling attackers to overwrite an arbitrary file via a symlink attack.
EPSS
Процентиль: 75%
0.01702
Низкий
5.5 Medium
CVSS2
6.5 Medium
CVSS3