NA

CVE-2024-34490

Published: 05/05/2024 Updated: 06/05/2024

Vulnerability Summary

In Maxima up to and including 5.47.0 prior to 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local attacker who can create files in advance with these names. This affects, for example, plot2d.

Vendor Advisories

Debian Bug report logs - #1071630 maxima: CVE-2024-34490 Package: src:maxima; Maintainer for src:maxima is Camm Maguire <camm@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 22 May 2024 15:21:02 UTC Severity: important Tags: security, upstream Found in versions maxima/5460-11, maxima/544 ...