Количество 4
Количество 4
CVE-2026-35357
The cp utility in uutils coreutils is vulnerable to an information disclosure race condition. Destination files are initially created with umask-derived permissions (e.g., 0644) before being restricted to their final mode (e.g., 0600) later in the process. A local attacker can race to open the file during this window; once obtained, the file descriptor remains valid and readable even after the permissions are tightened, exposing sensitive or private file contents.
CVE-2026-35357
The cp utility in uutils coreutils is vulnerable to an information disclosure race condition. Destination files are initially created with umask-derived permissions (e.g., 0644) before being restricted to their final mode (e.g., 0600) later in the process. A local attacker can race to open the file during this window; once obtained, the file descriptor remains valid and readable even after the permissions are tightened, exposing sensitive or private file contents.
CVE-2026-35357
The cp utility in uutils coreutils is vulnerable to an information dis ...
GHSA-2m8x-mvfx-gwgj
uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-35357 The cp utility in uutils coreutils is vulnerable to an information disclosure race condition. Destination files are initially created with umask-derived permissions (e.g., 0644) before being restricted to their final mode (e.g., 0600) later in the process. A local attacker can race to open the file during this window; once obtained, the file descriptor remains valid and readable even after the permissions are tightened, exposing sensitive or private file contents. | CVSS3: 4.7 | 0% Низкий | 3 месяца назад | |
CVE-2026-35357 The cp utility in uutils coreutils is vulnerable to an information disclosure race condition. Destination files are initially created with umask-derived permissions (e.g., 0644) before being restricted to their final mode (e.g., 0600) later in the process. A local attacker can race to open the file during this window; once obtained, the file descriptor remains valid and readable even after the permissions are tightened, exposing sensitive or private file contents. | CVSS3: 4.7 | 0% Низкий | 3 месяца назад | |
CVE-2026-35357 The cp utility in uutils coreutils is vulnerable to an information dis ... | CVSS3: 4.7 | 0% Низкий | 3 месяца назад | |
GHSA-2m8x-mvfx-gwgj uutils coreutils has a Time-of-check Time-of-use (TOCTOU) Race Condition | CVSS3: 4.7 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу