pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
References
Link | Resource |
---|---|
https://security-tracker.debian.org/tracker/CVE-2010-4817 | Third Party Advisory |
https://access.redhat.com/security/cve/cve-2010-4817 | Broken Link |
https://people.canonical.com/~ubuntu-security/cve/2010/CVE-2010-4817.html | Third Party Advisory |
https://www.openwall.com/lists/oss-security/2011/08/19/10 | Mailing List Third Party Advisory |
https://bugs.launchpad.net/pithos/%2Bbug/667896 | Issue Tracking Third Party Advisory |
Information
Published : 2019-11-13 14:15
Updated : 2019-11-25 08:09
NVD link : CVE-2010-4817
Mitre link : CVE-2010-4817
JSON object : View
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
Products Affected
debian
- debian_linux
pithos_project
- pithos