PT-2017-9713 · Gnu+1 · Gnu Guile+1

Publicado

2016-10-23

·

Atualizado

2024-06-15

·

CVE-2016-8605

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GNU Guile versions prior to 2.0.13
Description The issue arises from the mkdir procedure in GNU Guile, which temporarily changes the process' umask to zero. In a multithreaded application, this time window allows other threads to create files with insecure permissions. For instance, using mkdir without specifying the mode argument results in directories being created with 0777 permissions.
Recommendations For versions prior to 2.0.13, update to Guile 2.0.13 to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-8605
DLA-666-1
MGASA-2016-0354
MGASA-2021-0340
OPENSUSE-SU-2023:0137-1
OPENSUSE-SU-2024:10389-1
OPENSUSE-SU-2024:10415-1
SUSE-SU-2017:0394-1
SUSE-SU-2017:0398-1
SUSE-SU-2017_0394-1
SUSE-SU-2017_0398-1
SUSE-SU-2020:1659-1
SUSE-SU-2020_1659-1

Produtos afetados

Gnu Guile
Suse