← Back

CVE-2016-8605

nvd nist
Published: Jan 12, 2017Modified: May 6, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777. This is fixed in Guile 2.0.13. Prior versions are affected.

Affected (4)

Products: Fedoraproject: Fedora · Gnu: Guile
1 product
Fedora
1 product
Guile
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 23
Version 24
Version 25
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.0.12

Related CWEs

Timeline

No history available yet.