SageMath FlintQS 1.0 relies on pathnames under TMPDIR (typically world-writable), which (for example) allows a local user to overwrite files with the privileges of a different user (who is running FlintQS).
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: mitre
Published: 2023-04-06T00:00:00.000Z
Updated: 2025-02-12T16:34:31.453Z
Reserved: 2023-04-06T00:00:00.000Z
Link: CVE-2023-29465

Updated: 2024-08-02T14:07:46.363Z

Status : Modified
Published: 2023-04-06T20:15:08.830
Modified: 2025-02-12T17:15:18.670
Link: CVE-2023-29465

No data.