Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-12779

Опубликовано: 07 июн. 2019
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 6.6
CVSS3: 7.1

Описание

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
cosmic

ignored

end of life
devel

not-affected

1.0.5-1
disco

ignored

end of life
eoan

not-affected

1.0.5-1
esm-infra-legacy/trusty

needed

esm-infra-legacy/xenial

needed

esm-infra/bionic

needed

esm-infra/focal

not-affected

1.0.5-1
esm-infra/xenial

ignored

end of ESM support, was needed

Показывать по

EPSS

Процентиль: 48%
0.00655
Низкий

6.6 Medium

CVSS2

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
больше 7 лет назад

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

CVSS3: 7.1
nvd
около 7 лет назад

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

CVSS3: 7.1
debian
около 7 лет назад

libqb before 1.0.5 allows local users to overwrite arbitrary files via ...

suse-cvrf
около 7 лет назад

Security update for libqb

suse-cvrf
около 7 лет назад

Security update for libqb

EPSS

Процентиль: 48%
0.00655
Низкий

6.6 Medium

CVSS2

7.1 High

CVSS3