Back to search
CVE-2014-2893
Published: Apr 23, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
The GetHTMLRunDir function in the scan-build utility in Clang 3.5 and earlier allows local users to obtain sensitive information or overwrite arbitrary files via a symlink attack on temporary directories with predictable names.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20140416 CVE request: insecure temporary file handling in clang's scan-build utility
mailing-list
x_refsource_MLIST
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744817
x_refsource_MISC
openSUSE-SU-2015:0245
vendor-advisory
x_refsource_SUSE
[oss-security] 20140420 Re: Bug#744817: CVE request: insecure temporary file handling in clang's scan-build utility
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now