Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2023-6597

Published: March 23, 2024Last modified: October 14, 2024

Description

An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.2, 3.11.8, 3.10.13, 3.9.18, and 3.8.18 and prior. The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are potentially able to modify permissions of files referenced by symlinks in some circumstances.

Severity score breakdown

ParameterValue
Base score7.8
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSpython3Fixed (3.11.8-r0)
Streampython3Fixed (3.12.3-r0)

References

ON THIS PAGE