CVE-2013-4116Link Following in Packaged Modules Project Node Packaged Modules

CWE-59Link Following10 documents7 sources
Severity
3.3LOWNVD
EPSS
0.1%
top 71.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateSep 1

Description

lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

CVSS vector

AV:L/AC:M/C:N/I:P/A:PExploitability: 3.4 | Impact: 4.9

Affected Packages3 packages

npmnpmjs/npm< 1.3.3
Debiannpmjs/npm< 1.3.10~dfsg-1+3

Patches

🔴Vulnerability Details

4
OSV
Local Privilege Escalation in npm2020-09-01
GHSA
Local Privilege Escalation in npm2020-09-01
OSV
CVE-2013-4116: lib/npm2014-04-22
CVEList
CVE-2013-4116: lib/npm2014-04-22

📋Vendor Advisories

2
Red Hat
npm: Insecure temporary directory generation2013-07-08
Debian
CVE-2013-4116: npm - lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to ove...2013

💬Community

3
Bugzilla
CVE-2013-4116 npm: Insecure temporary directory generation2013-07-12
Bugzilla
npm: CVE-2013-4116 npm: Insecure temporary directory generation [epel-6]2013-07-12
Bugzilla
npm: CVE-2013-4116 npm: Insecure temporary directory generation [fedora-all]2013-07-12
CVE-2013-4116 — Link Following | cvebase