PT-2017-9713 · Gnu+1 · Gnu Guile+1

Published

2016-10-23

·

Updated

2024-06-15

·

CVE-2016-8605

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GNU Guile versions prior to 2.0.13
Description The issue arises from the mkdir procedure in GNU Guile, which temporarily changes the process' umask to zero. In a multithreaded application, this time window allows other threads to create files with insecure permissions. For instance, using mkdir without specifying the mode argument results in directories being created with 0777 permissions.
Recommendations For versions prior to 2.0.13, update to Guile 2.0.13 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-8605
DLA-666-1
MGASA-2016-0354
MGASA-2021-0340
OPENSUSE-SU-2023:0137-1
OPENSUSE-SU-2024:10389-1
OPENSUSE-SU-2024:10415-1
SUSE-SU-2017:0394-1
SUSE-SU-2017:0398-1
SUSE-SU-2017_0394-1
SUSE-SU-2017_0398-1
SUSE-SU-2020:1659-1
SUSE-SU-2020_1659-1

Affected Products

Gnu Guile
Suse