cbcvebase.
CVE-2010-4337
published 2011-01-14

CVE-2010-4337: The configure script in gnash 0.8.8 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/gnash-configure-errors.$$, (2)…

PriorityP48low3.3CVSS 2.0
AVLACMAuNCNIPAP
EPSS
0.34%
26.1th percentile
The configure script in gnash 0.8.8 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/gnash-configure-errors.$$, (2) /tmp/gnash-configure-warnings.$$, or (3) /tmp/gnash-configure-recommended.$$ files.

Affected

3 ranges
VendorProductVersion rangeFixed in
gnugnash
gnugnash>= 0 < 0.8.11~git20130903-3ubuntu10.8.11~git20130903-3ubuntu1
gnugnash>= 0 < 0.8.11~git20160109-1build10.8.11~git20160109-1build1

CVSS provenance

nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.