Beveiligingsadvies

CVE-2013-0162

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2013-03-01 02:00:00
Laatst bijgewerkt 2024-08-06 14:18:09
Toegewezen door redhat
CVSS-score geen score
Status PUBLISHED

Beschrijving

The diff_pp function in lib/gauntlet_rubyparser.rb in the ruby_parser gem 3.1.1 and earlier for Ruby allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.