libs/updater.py in GoLismero 0.6.3, and other versions...
Low severity
Unreviewed
Published
May 4, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Mar 19, 2012
Published to the GitHub Advisory Database
May 4, 2022
Last updated
Feb 1, 2023
libs/updater.py in GoLismero 0.6.3, and other versions before Git revision 2b3bb43d6867, as used in backtrack and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on GoLismero-controlled files, as demonstrated using Admin/changes.dat.
References