392
VMScore

CVE-2021-44512

Published: 07/12/2021 Updated: 03/05/2022
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local malicious user to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this directory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tmate tmate-ssh-server

Vendor Advisories

Debian Bug report logs - #1001225 tmate-ssh-server: CVE-2021-44512 CVE-2021-44513 Package: src:tmate-ssh-server; Maintainer for src:tmate-ssh-server is Adrian Vondendriesch <adrianvondendriesch@credativde>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 6 Dec 2021 16:12:01 UTC Severity: grave Tag ...