Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-4116

Опубликовано: 22 апр. 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 3.3

Описание

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

3.5.2-0ubuntu4
devel

not-affected

3.5.2-0ubuntu4
esm-apps/bionic

not-affected

3.5.2-0ubuntu4
esm-apps/xenial

not-affected

3.5.2-0ubuntu4
esm-infra-legacy/trusty

not-affected

1.3.10~dfsg-1
lucid

DNE

precise

ignored

end of life
precise/esm

DNE

precise was needs-triage
quantal

ignored

end of life

Показывать по

3.3 Low

CVSS2

Связанные уязвимости

redhat
больше 12 лет назад

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

nvd
почти 12 лет назад

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

debian
почти 12 лет назад

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local us ...

github
больше 5 лет назад

Local Privilege Escalation in npm

3.3 Low

CVSS2