Lucene search

K
osvGoogleOSV:RUSTSEC-2021-0102
HistoryMay 27, 2021 - 12:00 p.m.

Permissions bypass in pleaser

2021-05-2712:00:00
Google
osv.dev
14
permissions bypass
pleaser 0.4
local attacker
root privileges
symlink attack
temporary filenames
software

EPSS

0

Percentile

5.1%

pleaseedit in pleaser before 0.4 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack.