Lucene search

K
githubGitHub Advisory DatabaseGHSA-RR52-WG7F-8875
HistoryMay 14, 2022 - 2:09 a.m.

Improper Link Resolution Before File Access in logilab-commons

2022-05-1402:09:22
CWE-59
GitHub Advisory Database
github.com
12
improper link resolution
file access
logilab-commons

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

5.1%

The (1) extract_keys_from_pdf and (2) fill_pdf functions in pdf_ext.py in logilab-common before 0.61.0 allows local users to overwrite arbitrary files and possibly have other unspecified impact via a symlink attack on /tmp/toto.fdf.

Affected configurations

Vulners
Node
logilablogilab-commonRange<0.61.0

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

EPSS

0

Percentile

5.1%