The diff_pp function in lib/gauntlet_rubyparser.rb in the ruby_parser gem 3.1.1 and earlier for Ruby allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2013-02-28 21:40
Updated : 2023-02-12 20:38
NVD link : CVE-2013-0162
Mitre link : CVE-2013-0162
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
ryan_davis
- ruby_parser