PT-2023-24735 · Imapsync · Imapsync
Orlitzky
·
Publicado
2023-05-30
·
Atualizado
2025-01-10
·
CVE-2023-34204
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
imapsync versions through 2.229
Description
The issue concerns the use of predictable paths under /tmp and /var/tmp in the default mode of operation. Since these paths are typically world-writable, an attacker can modify imapsync's cache and overwrite files belonging to the user who runs it.
Recommendations
For versions through 2.229, consider changing the default temporary directories to a more secure location that is not world-writable, or apply specific permissions to restrict access to these directories until a patch is available.
Exploit
Correção
Link Following
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Imapsync