3.5
CVSSv3

CVE-2016-10538

Published: 31/05/2018 Updated: 09/10/2019
CVSS v2 Base Score: 4.9 | Impact Score: 4.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 3.5 | Impact Score: 1.4 | Exploitability Score: 2.1
VMScore: 436
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:P

Vulnerability Summary

The package `node-cli` prior to 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cli project cli

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #809252 node-cli: CVE-2016-10538 Package: node-cli; Maintainer for node-cli is Debian Javascript Maintainers <pkg-javascript-devel@listsaliothdebianorg>; Source for node-cli is src:node-cli (PTS, buildd, popcon) Reported by: Steve Kemp <steve@steveorguk> Date: Mon, 28 Dec 2015 18:33:02 U ...