Vulnerability Name: | CVE-2013-1809 (CCN-171268) | ||||||||||||||||||||||||||||
Assigned: | 2013-03-04 | ||||||||||||||||||||||||||||
Published: | 2013-03-04 | ||||||||||||||||||||||||||||
Updated: | 2020-08-18 | ||||||||||||||||||||||||||||
Summary: | Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-59 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-1809 Source: MISC Type: Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2013/03/03/4 Source: MISC Type: Not Applicable, Third Party Advisory https://access.redhat.com/security/cve/cve-2013-1809 Source: CCN Type: Red Hat Bugzilla - Bug 917751 (CVE-2013-1809) - CVE-2013-1809 gambas3: insecure temporary directories flaw Source: MISC Type: Issue Tracking, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-1809 Source: CCN Type: Gambas Project Web site Gambas Source: MISC Type: Issue Tracking, Third Party Advisory https://code.google.com/archive/p/gambas/issues/365 Source: XF Type: UNKNOWN gambas-cve20131809-sec-bypass(171268) Source: MISC Type: Third Party Advisory https://security-tracker.debian.org/tracker/CVE-2013-1809 Source: CONFIRM Type: Patch, Third Party Advisory https://sourceforge.net/p/gambas/code/5438/ | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |