[Secure-testing-team] Bug#870852: rubocop: CVE-2017-8418
Salvatore Bonaccorso
carnil at debian.org
Sat Aug 5 19:36:20 UTC 2017
Source: rubocop
Version: 0.48.1+dfsg-1
Severity: grave
Tags: patch security upstream
Forwarded: https://github.com/bbatsov/rubocop/issues/4336
Hi,
the following vulnerability was published for rubocop.
CVE-2017-8418[0]:
| RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing
| local users to exploit this to tamper with cache files belonging to
| other users.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2017-8418
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-8418
[1] https://github.com/bbatsov/rubocop/issues/4336
Regards,
Salvatore
More information about the Secure-testing-team
mailing list