PT-2014-4323 · Logilab+1 · Logilab-Common+1

Jakub Wilk

·

Published

2014-03-03

·

Updated

2024-07-12

·

CVE-2014-1839

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions logilab-common versions prior to 0.61.0
Description The Execute class in shellutils in logilab-common uses tempfile.mktemp, which allows local users to have an unspecified impact by pre-creating the temporary file.
Recommendations For versions prior to 0.61.0, update to version 0.61.0 or later to resolve the issue.

Fix

Weakness Enumeration

Related Identifiers

CVE-2014-1839
GHSA-G5M2-22H2-RR3J
MGASA-2014-0118
OPENSUSE-SU-2024:10400-1
OPENSUSE-SU-2024:11235-1
OPENSUSE-SU-2024:14145-1
PYSEC-2014-84

Affected Products

Suse
Logilab-Common