The Execute class in shellutils in logilab-commons before 0.61.0 uses tempfile.mktemp, which allows local users to have an unspecified impact by pre-creating the temporary file.
References
Configurations
History
21 Nov 2024, 02:05
Type | Values Removed | Values Added |
---|---|---|
References | () http://comments.gmane.org/gmane.comp.security.oss.general/11986 - | |
References | () http://lists.opensuse.org/opensuse-updates/2014-02/msg00085.html - | |
References | () http://secunia.com/advisories/57209 - Vendor Advisory | |
References | () http://www.logilab.org/ticket/207562 - | |
References | () https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737051 - |
Information
Published : 2014-03-11 19:37
Updated : 2024-11-21 02:05
NVD link : CVE-2014-1839
Mitre link : CVE-2014-1839
CVE.ORG link : CVE-2014-1839
JSON object : View
Products Affected
logilab
- logilab-common
opensuse
- opensuse
CWE