PT-2024-36558 · Colpack+1 · Colpack+1

Wolfgang Frisch

·

Published

2024-12-09

·

Updated

2024-12-17

·

CVE-2024-55566

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions ColPack versions 1.0.10 through 9a7293a
Description The issue is related to the creation of predictable temporary files in ColPack, located under /tmp with names derived from an unseeded Random Number Generator (RNG). This can lead to overwriting files or making ColPack graphing unavailable to other users.
Recommendations For ColPack versions 1.0.10 through 9a7293a, consider restricting access to the /tmp directory to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using ColPack graphing functionality that relies on temporary files in /tmp until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-55566

Affected Products

Colpack
Debian