Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45440
HistoryFeb 12, 2024 - 7:37 a.m.

Code Injection

2024-02-1207:37:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
vulnerability
hardcoded directory
native code packages
shared
users
malicious
maintainers deprecated
no patch

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

pkg is vulnerable toCode Injection. The vulnerability is due to the use of a hardcoded directory (/tmp/pkg/*) for native code packages, which is shared among all users on the same local system without unique or unpredictable package names, enabling attackers to replace genuine executables with malicious ones. Please note that the maintainers have deprecated the package, meaning no patch will be released for this issue.

CPENameOperatorVersion
pkgle5.8.1
pkgle5.8.1

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%