cbcvebase.
CVE-2015-7758
published 2016-01-08

CVE-2015-7758: Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the name of an existing file and a (1) .aux…

PriorityP412low3.3CVSS 3.0
AVLACLPRLUINSUCNILAN
EPSS
0.39%
32.1th percentile
Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the name of an existing file and a (1) .aux, (2) .log, (3) .out, (4) .pdf, or (5) .toc extension for the file name, as demonstrated by .thesis.tex.aux.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiangummi< gummi 0.6.5-6 (bookworm)gummi 0.6.5-6 (bookworm)
gummi_projectgummi
gummi_projectgummi>= 0 < 0.6.5-60.6.5-6
gummi_projectgummi>= 0 < 0.6.5-60.6.5-6
gummi_projectgummi>= 0 < 0.6.5-60.6.5-6
gummi_projectgummi>= 0 < 0.6.5-60.6.5-6
opensuseleap
opensuseopensuse
opensuseopensuse

CVSS provenance

nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv3.3LOW
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.