5.5
CVSSv3

CVE-2012-6114

Published: 28/01/2020 Updated: 07/02/2020
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/changelog or (2) /tmp/.git-effort.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

git-extras project git-extras 1.7.0

Vendor Advisories

Debian Bug report logs - #698490 git-effort/git-changelog: predictable /tmp filenames (CVE-2012-6114) Package: git-extras; Maintainer for git-extras is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Source for git-extras is src:git-extras (PTS, buildd, popcon) Reported by: Helmut Grohne <helmut@subdivide> Date: Sat, 19 ...