Zim through 0.72.1 creates temporary directories with predictable names. A malicious user could predict and create Zim's temporary directories and prevent other users from being able to start Zim, resulting in a denial of service.
References
Link | Resource |
---|---|
https://github.com/zim-desktop-wiki/zim-desktop-wiki/issues/1028 | Third Party Advisory |
https://github.com/zim-desktop-wiki/zim-desktop-wiki/issues/1028 | Third Party Advisory |
Configurations
History
21 Nov 2024, 04:56
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/zim-desktop-wiki/zim-desktop-wiki/issues/1028 - Third Party Advisory |
Information
Published : 2020-03-23 20:15
Updated : 2024-11-21 04:56
NVD link : CVE-2020-10870
Mitre link : CVE-2020-10870
CVE.ORG link : CVE-2020-10870
JSON object : View
Products Affected
zim-wiki
- zim
CWE
CWE-330
Use of Insufficiently Random Values