Количество 4
Количество 4
CVE-2026-35356
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the install utility of uutils coreutils when using the -D flag. The command creates parent directories and subsequently performs a second path resolution to create the target file, neither of which is anchored to a directory file descriptor. An attacker with concurrent write access can replace a path component with a symbolic link between these operations, redirecting the privileged write to an arbitrary file system location.
CVE-2026-35356
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the install utility of uutils coreutils when using the -D flag. The command creates parent directories and subsequently performs a second path resolution to create the target file, neither of which is anchored to a directory file descriptor. An attacker with concurrent write access can replace a path component with a symbolic link between these operations, redirecting the privileged write to an arbitrary file system location.
CVE-2026-35356
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the in ...
GHSA-gwm6-q8ch-hcfr
install -D: symlink race in directory creation allows arbitrary file overwrite
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-35356 A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the install utility of uutils coreutils when using the -D flag. The command creates parent directories and subsequently performs a second path resolution to create the target file, neither of which is anchored to a directory file descriptor. An attacker with concurrent write access can replace a path component with a symbolic link between these operations, redirecting the privileged write to an arbitrary file system location. | CVSS3: 6.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-35356 A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the install utility of uutils coreutils when using the -D flag. The command creates parent directories and subsequently performs a second path resolution to create the target file, neither of which is anchored to a directory file descriptor. An attacker with concurrent write access can replace a path component with a symbolic link between these operations, redirecting the privileged write to an arbitrary file system location. | CVSS3: 6.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-35356 A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in the in ... | CVSS3: 6.3 | 0% Низкий | 4 месяца назад | |
GHSA-gwm6-q8ch-hcfr install -D: symlink race in directory creation allows arbitrary file overwrite | CVSS3: 6.3 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу