w3m CVE-2018-6198 Insecure Temporary File Handling Vulnerability
BID:102855
CVE-2018-6198 |Info
w3m CVE-2018-6198 Insecure Temporary File Handling Vulnerability
| Bugtraq ID: | 102855 |
| Class: | Design Error |
| CVE: |
CVE-2018-6198 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 23 2018 12:00AM |
| Updated: | Jan 23 2018 12:00AM |
| Credit: | Tatsuya Kinoshita |
| Vulnerable: |
W3M W3M 0.5.3 W3M W3M 0.5.2 W3M W3M 0.5.1 W3M W3M 0.3.2 W3M W3M 0.3.1 W3M W3M 0.3 W3M W3M 0.2.5 W3M W3M 0.2.4 W3M W3M 0.2.3 W3M W3M 0.2.2 W3M W3M 0.2.1 W3M W3M 0.2 W3M W3M 0.1.10 W3M W3M 0.1.9 W3M W3M 0.1.8 W3M W3M 0.1.7 W3M W3M 0.1.6 W3M W3M 0.1.4 W3M W3M 0.1.3 Redhat Enterprise Linux 6 Redhat Enterprise Linux 5 |
| Not Vulnerable: | |
Discussion
w3m CVE-2018-6198 Insecure Temporary File Handling Vulnerability
w3m is prone to an insecure temporary file-handling vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
w3m is prone to an insecure temporary file-handling vulnerability.
An attacker with local access could potentially exploit this issue to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Exploit / POC
w3m CVE-2018-6198 Insecure Temporary File Handling Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
w3m CVE-2018-6198 Insecure Temporary File Handling Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
w3m CVE-2018-6198 Insecure Temporary File Handling Vulnerability
References:
References: