3.3
CVSSv2

CVE-2013-4116

Published: 22/04/2014 Updated: 14/10/2020
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

lib/npm.js in Node Packaged Modules (npm) prior to 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

node packaged modules project node packaged modules

Vendor Advisories

Debian Bug report logs - #715325 npm: CVE-2013-4116: predictable temporary filenames when unpacking tarballs Package: npm; Maintainer for npm is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Source for npm is src:npm (PTS, buildd, popcon) Reported by: Shawn Landden <shawnlandden@gmailcom&g ...
lib/npmjs in Node Packaged Modules (npm) before 133 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives ...