← Back

CVE-2015-7758

nvd nist
Published: Jan 8, 2016Modified: May 6, 2026

JSON object

Loading...
3.3
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 1.8 / Impact: 1.4
Source: NVD

Description

Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the name of an existing file and a (1) .aux, (2) .log, (3) .out, (4) .pdf, or (5) .toc extension for the file name, as demonstrated by .thesis.tex.aux.

Affected (4)

2 products
Leap
Opensuse
1 product
Gummi
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Version 42.1
Opensuse
Version 13.1
Version 13.2
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 0.6.5

Timeline

No history available yet.