Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-18196

Опубликовано: 23 фев. 2018
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 2.1
CVSS3: 3.3

Описание

Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

1.75.3-2
cosmic

not-affected

1.75.3-2
devel

not-affected

1.75.3-2
disco

not-affected

1.75.3-2
eoan

not-affected

1.75.3-2
esm-apps/bionic

not-affected

1.75.3-2
esm-apps/focal

not-affected

1.75.3-2
esm-apps/jammy

not-affected

1.75.3-2
esm-apps/xenial

released

1.73-1ubuntu0.1~esm1

Показывать по

EPSS

Процентиль: 18%
0.00056
Низкий

2.1 Low

CVSS2

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
nvd
почти 8 лет назад

Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.

CVSS3: 3.3
debian
почти 8 лет назад

Leptonica 1.74.4 constructs unintended pathnames (containing duplicate ...

CVSS3: 3.3
github
больше 3 лет назад

Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.

EPSS

Процентиль: 18%
0.00056
Низкий

2.1 Low

CVSS2

3.3 Low

CVSS3