PT-2019-6797 · Libuser · Libuser
Florian Weimer
+1
·
Publicado
2019-11-25
·
Atualizado
2019-12-04
·
CVE-2012-5630
CVSS v3.1
6.3
Média
| Vetor | AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libuser versions 0.56 through 0.57
Description
The issue is related to a TOCTOU (time-of-check time-of-use) race condition that occurs when copying and removing directory trees.
Recommendations
For versions 0.56 and 0.57, consider implementing additional checks to mitigate the TOCTOU race condition until a patch is available.
As a temporary workaround, consider restricting access to the directory tree operations to minimize the risk of exploitation.
Correção
Time Of Check To Time Of Use
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Libuser