CVE-2020-10870

Zim through 0.72.1 creates temporary directories with predictable names. A malicious user could predict and create Zim's temporary directories and prevent other users from being able to start Zim, resulting in a denial of service.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zim-wiki:zim:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:56

Type Values Removed Values Added
References () https://github.com/zim-desktop-wiki/zim-desktop-wiki/issues/1028 - Third Party Advisory () https://github.com/zim-desktop-wiki/zim-desktop-wiki/issues/1028 - Third Party Advisory

Information

Published : 2020-03-23 20:15

Updated : 2024-11-21 04:56


NVD link : CVE-2020-10870

Mitre link : CVE-2020-10870

CVE.ORG link : CVE-2020-10870


JSON object : View

Products Affected

zim-wiki

  • zim
CWE
CWE-330

Use of Insufficiently Random Values