Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Jérémy Lal

#52972de 53,635
3.3CVSS total
Vulnerabilidades · 1
PT-2014-2739
3.3
2014-04-22
Node · Npm · CVE-2013-4116
**Name of the Vulnerable Software and Affected Versions** Node Packaged Modules (npm) versions prior to 1.3.3 **Description** The issue allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives. This can potentially result in local privilege escalation. **Recommendations** Update to version 1.3.3 or later.