Lucene search

K
gentooGentoo FoundationGLSA-202407-18
HistoryJul 05, 2024 - 12:00 a.m.

Stellarium: Arbitrary File Write

2024-07-0500:00:00
Gentoo Foundation
security.gentoo.org
stellarium
file write
vulnerability
attackers
upgrade
resolution

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.9

Confidence

Low

Background

Stellarium is a free open source planetarium for your computer. It shows a realistic sky in 3D, just like what you see with the naked eye, binoculars or a telescope.

Description

A vulnerability has been discovered in Stellarium. Please review the CVE identifier referenced below for details.

Impact

Attackers can write to files that are typically unintended, such as ones with absolute pathnames or … directory traversal.

Workaround

There is no known workaround at this time.

Resolution

All Stellarium users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=sci-astronomy/stellarium-23.1"
OSVersionArchitecturePackageVersionFilename
Gentooanyallsci-astronomy/stellarium< 23.1UNKNOWN

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

6.9

Confidence

Low