Vulnerability Name: | CVE-2014-0177 (CCN-94069) | ||||||||||||||||||||||||||||
Assigned: | 2013-12-03 | ||||||||||||||||||||||||||||
Published: | 2014-05-16 | ||||||||||||||||||||||||||||
Updated: | 2023-06-06 | ||||||||||||||||||||||||||||
Summary: | hub could allow a local attacker to launch a symlink attack. The am function in lib/hub/commands.rb creates temporary files insecurely. A local attacker could exploit this vulnerability by creating a symbolic link from a temporary file to various files on the system, which could allow the attacker to overwrite arbitrary files on the system with elevated privileges. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 3.6 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P) 3.1 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:C)
2.9 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||||||||||||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-0177 Source: CCN Type: oss-security Mailing List, Fri, 16 May 2014 21:43:45 +0200 Small security issue in hub, a github client ( CVE-2014-0177 ) Source: CCN Type: BID-67474 Hub CVE-2014-0177 Insecure Temporary File Creation Vulnerability Source: XF Type: UNKNOWN hub-cve20140177-symlink(94069) Source: CCN Type: hub GIT Repository hub Source: secalert@redhat.com Type: Exploit, Patch secalert@redhat.com | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |