Zim through 0.72.1 creates temporary directories with predictable names. A malicious user could predict and create Zim's temporary directories and prevent other users from being able to start Zim, resulting in a denial of service.
References
Link | Resource |
---|---|
https://github.com/zim-desktop-wiki/zim-desktop-wiki/issues/1028 | Third Party Advisory |
Configurations
Information
Published : 2020-03-23 13:15
Updated : 2021-07-21 04:39
NVD link : CVE-2020-10870
Mitre link : CVE-2020-10870
JSON object : View
CWE
CWE-330
Use of Insufficiently Random Values
Products Affected
zim-wiki
- zim