Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-7039

Опубликовано: 03 сент. 2025
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 3.7

Описание

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.

РелизСтатусПримечание
devel

not-affected

2.85.2-2
esm-infra-legacy/trusty

released

2.40.2-0ubuntu1.1+esm7
esm-infra/bionic

released

2.56.4-0ubuntu0.18.04.9+esm5
esm-infra/focal

released

2.64.6-1~ubuntu20.04.9+esm1
esm-infra/xenial

released

2.48.2-0ubuntu4.8+esm5
jammy

released

2.72.4-0ubuntu2.7
noble

released

2.80.0-6ubuntu3.6
plucky

released

2.84.1-1ubuntu0.2
questing

not-affected

2.85.2-2
upstream

released

2.84.4-1

Показывать по

EPSS

Процентиль: 14%
0.00044
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
redhat
9 месяцев назад

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.

CVSS3: 3.7
nvd
7 месяцев назад

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.

CVSS3: 3.7
msrc
7 месяцев назад

Glib: buffer under-read on glib through glib/gfileutils.c via get_tmp_file()

CVSS3: 3.7
debian
7 месяцев назад

A flaw was found in glib. An integer overflow during temporary file cr ...

suse-cvrf
4 месяца назад

Security update for glib2

EPSS

Процентиль: 14%
0.00044
Низкий

3.7 Low

CVSS3