3.3
CVSSv2

CVE-2012-2093

Published: 18/05/2012 Updated: 29/08/2017
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

src/common/latex.py in Gajim 0.15 allows local users to overwrite arbitrary files via a symlink attack on a temporary latex file, related to the get_tmpfile_name function.

Vulnerable Product Search on Vulmon Subscribe to Product

gajim gajim 0.15

Vendor Advisories

Debian Bug report logs - #668038 gajim code execution and sql injection Package: gajim; Maintainer for gajim is Debian XMPP Maintainers <pkg-xmpp-devel@listsaliothdebianorg>; Source for gajim is src:gajim (PTS, buildd, popcon) Reported by: "Thijs Kinkhorst" <thijs@debianorg> Date: Sun, 8 Apr 2012 13:51:02 UTC S ...
Debian Bug report logs - #668710 gajim: CVE-2012-2093 insecure temporary file creation in LaTeX support Package: gajim; Maintainer for gajim is Debian XMPP Maintainers <pkg-xmpp-devel@listsaliothdebianorg>; Source for gajim is src:gajim (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Sat, 14 ...
Several vulnerabilities have been discovered in Gajim, a feature-rich Jabber client The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2012-1987 Gajim is not properly sanitizing input before passing it to shell commands An attacker can use this flaw to execute arbitrary code on behalf of the victi ...