Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-8605

Опубликовано: 12 янв. 2017
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5
CVSS3: 5.3

Описание

The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777. This is fixed in Guile 2.0.13. Prior versions are affected.

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-apps/xenial

needed

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
esm-infra/focal

DNE

focal

DNE

Показывать по

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

2.0.13+1-1
cosmic

not-affected

2.0.13+1-1
devel

DNE

disco

not-affected

2.0.13+1-1
eoan

not-affected

2.0.13+1-1
esm-apps/focal

not-affected

2.0.13+1-1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
esm-infra/bionic

not-affected

2.0.13+1-1
esm-infra/xenial

needed

Показывать по

Ссылки на источники

EPSS

Процентиль: 25%
0.00089
Низкий

5 Medium

CVSS2

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 2.5
redhat
больше 9 лет назад

The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777. This is fixed in Guile 2.0.13. Prior versions are affected.

CVSS3: 5.3
nvd
около 9 лет назад

The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777. This is fixed in Guile 2.0.13. Prior versions are affected.

CVSS3: 5.3
debian
около 9 лет назад

The mkdir procedure of GNU Guile temporarily changed the process' umas ...

suse-cvrf
почти 9 лет назад

Security update for guile

suse-cvrf
больше 9 лет назад

Security update for guile1

EPSS

Процентиль: 25%
0.00089
Низкий

5 Medium

CVSS2

5.3 Medium

CVSS3