CVE-2013-4116
published 2014-04-22CVE-2013-4116: lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable…
PriorityP49low3.3CVSS 2.0
AVLACMAuNCNIPAP
EPSS
0.37%
29.5th percentile
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | npm | < npm 1.3.10~dfsg-1 (bookworm) | npm 1.3.10~dfsg-1 (bookworm) |
| node_packaged_modules_project | node_packaged_modules | < 1.3.3 | 1.3.3 |
| npmjs | npm | >= 0 < 1.3.10~dfsg-1 | 1.3.10~dfsg-1 |
| npmjs | npm | >= 0 < 1.3.10~dfsg-1 | 1.3.10~dfsg-1 |
| npmjs | npm | >= 0 < 1.3.10~dfsg-1 | 1.3.10~dfsg-1 |
| npmjs | npm | >= 0 < 1.3.10~dfsg-1 | 1.3.10~dfsg-1 |
| npmjs | npm | >= 0 < 1.3.3 | 1.3.3 |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Local Privilege Escalation in npm
osv·2020-09-01
CVE-2013-4116 [LOW] Local Privilege Escalation in npm
Local Privilege Escalation in npm
Affected versions of `npm` use predictable temporary file names during archive unpacking. If an attacker can create a symbolic link at the location of one of these temporary file names, the attacker can arbitrarily write to any file that the user which owns the `npm` process has permission to write to, potentially resulting in local privilege escalation.
## Recommendation
Update to version 1.3.3 or later.
GHSA
Local Privilege Escalation in npm
ghsa·2020-09-01
CVE-2013-4116 [LOW] CWE-59 Local Privilege Escalation in npm
Local Privilege Escalation in npm
Affected versions of `npm` use predictable temporary file names during archive unpacking. If an attacker can create a symbolic link at the location of one of these temporary file names, the attacker can arbitrarily write to any file that the user which owns the `npm` process has permission to write to, potentially resulting in local privilege escalation.
## Recommendation
Update to version 1.3.3 or later.
OSV
CVE-2013-4116: lib/npm
osv·2014-04-22·CVSS 3.3
CVE-2013-4116 [LOW] CVE-2013-4116: lib/npm
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.
Red Hat
npm: Insecure temporary directory generation
vendor_redhat·2013-07-08·CVSS 3.3
CVE-2013-4116 [LOW] npm: Insecure temporary directory generation
npm: Insecure temporary directory generation
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.
Package: nodejs010-npm (Red Hat Software Collections) - Affected
Debian
CVE-2013-4116: npm - lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to ove...
vendor_debian·2013·CVSS 3.3
CVE-2013-4116 [LOW] CVE-2013-4116: npm - lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to ove...
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.
Scope: local
bookworm: resolved (fixed in 1.3.10~dfsg-1)
bullseye: resolved (fixed in 1.3.10~dfsg-1)
forky: resolved (fixed in 1.3.10~dfsg-1)
sid: resolved (fixed in 1.3.10~dfsg-1)
trixie: resolved (fixed in 1.3.10~dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4116 npm: Insecure temporary directory generation
bugzilla·2013-07-12·CVSS 3.3
CVE-2013-4116 [LOW] CVE-2013-4116 npm: Insecure temporary directory generation
CVE-2013-4116 npm: Insecure temporary directory generation
An insecure temporary directory generation / use flaw was found in the way NPM, Node.js Package Manager, used to generate location of the temporary folder to be used for tarballs expansion. A local attacker could use this flaw to conduct symbolic link attacks, possibly leading to their ability to overwrite arbitrary system file reachable with the privileges of the user performing the NPM archive expansion.
References:
[1] http://www.openwall.com/lists/oss-security/2013/07/10/17
[2] http://www.openwall.com/lists/oss-security/2013/07/10/18
[3] http://www.openwall.com/lists/oss-security/2013/07/11/9
Upstream bug report:
[4] https://github.com/isaacs/npm/issues/3635
Relevant upstream patch:
[5] https://github.com/isaacs/npm/commit/
Bugzilla
npm: CVE-2013-4116 npm: Insecure temporary directory generation [epel-6]
bugzilla·2013-07-12·CVSS 3.3
CVE-2013-4116 [LOW] npm: CVE-2013-4116 npm: Insecure temporary directory generation [epel-6]
npm: CVE-2013-4116 npm: Insecure temporary directory generation [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for npm
Bugzilla
npm: CVE-2013-4116 npm: Insecure temporary directory generation [fedora-all]
bugzilla·2013-07-12·CVSS 3.3
CVE-2013-4116 [LOW] npm: CVE-2013-4116 npm: Insecure temporary directory generation [fedora-all]
npm: CVE-2013-4116 npm: Insecure temporary directory generation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affe
http://www.openwall.com/lists/oss-security/2013/07/10/17http://www.openwall.com/lists/oss-security/2013/07/11/9http://www.securityfocus.com/bid/61083https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=715325https://bugzilla.redhat.com/show_bug.cgi?id=983917https://exchange.xforce.ibmcloud.com/vulnerabilities/87141https://github.com/npm/npm/commit/f4d31693https://github.com/npm/npm/issues/3635http://www.openwall.com/lists/oss-security/2013/07/10/17http://www.openwall.com/lists/oss-security/2013/07/11/9http://www.securityfocus.com/bid/61083https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=715325https://bugzilla.redhat.com/show_bug.cgi?id=983917https://exchange.xforce.ibmcloud.com/vulnerabilities/87141https://github.com/npm/npm/commit/f4d31693https://github.com/npm/npm/issues/3635
2014-04-22
Published