Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-0177
HistoryMay 27, 2014 - 12:00 a.m.

CVE-2014-0177

2014-05-2700:00:00
ubuntu.com
ubuntu.com
7

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

EPSS

0

Percentile

5.1%

The am function in lib/hub/commands.rb in hub before 1.12.1 allows local
users to overwrite arbitrary files via a symlink attack on a temporary
patch file.

Notes

Author Note
msalvatore hub is not in Ubuntu

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

EPSS

0

Percentile

5.1%

Related for UB:CVE-2014-0177