PT-2022-25335 · Singular+2 · Singular+2
Orlitzky
·
Published
2022-09-09
·
Updated
2026-04-29
·
CVE-2022-40299
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Singular versions prior to 4.3.1
Description
The issue is related to the use of predictable /tmp pathnames in files such as sdb.cc within the Singular interface. This predictability allows local users to gain the privileges of other users via a procedure in a file under /tmp. The problem specifically concerns the handling of temporary files by certain files in the Singular interface, not the lack of a safe temporary-file creation capability in the Singular language itself.
Recommendations
For versions prior to 4.3.1, update to version 4.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to files under /tmp that are used by the Singular interface, such as those accessed by sdb.cc, to minimize the risk of exploitation.
Exploit
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Singular