Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-4116

Опубликовано: 22 апр. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 3.3

Описание

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

3.5.2-0ubuntu4
devel

not-affected

3.5.2-0ubuntu4
esm-apps-legacy/xenial

not-affected

3.5.2-0ubuntu4
esm-apps/bionic

not-affected

3.5.2-0ubuntu4
esm-apps/xenial

not-affected

3.5.2-0ubuntu4
esm-infra-legacy/trusty

not-affected

1.3.10~dfsg-1
lucid

DNE

precise

ignored

end of life
precise/esm

DNE

precise was needs-triage

Показывать по

EPSS

Процентиль: 30%
0.00372
Низкий

3.3 Low

CVSS2

Связанные уязвимости

redhat
около 13 лет назад

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

nvd
больше 12 лет назад

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

debian
больше 12 лет назад

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local us ...

github
почти 6 лет назад

Local Privilege Escalation in npm

EPSS

Процентиль: 30%
0.00372
Низкий

3.3 Low

CVSS2