The am
function in lib/hub/commands.rb
in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file.
github.com/github/hub/commit/016ec99d25b1cb83cb4367e541177aa431beb600
github.com/mislav/hub
github.com/mislav/hub/commit/016ec99d25b1cb83cb4367e541177aa431beb600
github.com/mislav/hub/releases/tag/v1.12.1
github.com/rubysec/ruby-advisory-db/blob/master/gems/hub/CVE-2014-0177.yml
nvd.nist.gov/vuln/detail/CVE-2014-0177