PT-2019-6797 · Libuser · Libuser
Florian Weimer
+1
·
Published
2019-11-25
·
Updated
2019-12-04
·
CVE-2012-5630
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
libuser versions 0.56 through 0.57
Description
The issue is related to a TOCTOU (time-of-check time-of-use) race condition that occurs when copying and removing directory trees.
Recommendations
For versions 0.56 and 0.57, consider implementing additional checks to mitigate the TOCTOU race condition until a patch is available.
As a temporary workaround, consider restricting access to the directory tree operations to minimize the risk of exploitation.
Fix
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libuser