Lucene search

K
mageiaGentoo FoundationMGASA-2023-0129
HistoryApr 07, 2023 - 12:20 a.m.

Updated stellarium packages fix security vulnerability

2023-04-0700:20:12
Gentoo Foundation
advisories.mageia.org
9
stellarium
security vulnerability
file write
absolute pathnames
directory traversal
cve-2023-28371
unix

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.004

Percentile

72.4%

Attackers can write to files that are typically unintended, such as ones with absolute pathnames or … directory traversal. (CVE-2023-28371)

OSVersionArchitecturePackageVersionFilename
Mageia8noarchstellarium< 0.21.3-1.1stellarium-0.21.3-1.1.mga8

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.004

Percentile

72.4%