CVE-2023-6597
Public on 2024-03-19
Modified on 2024-03-28
Description
An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.2, 3.11.8, 3.10.13, 3.9.18, and 3.8.18 and prior.
The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are potentially able to modify permissions of files referenced by symlinks in some circumstances.
The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are potentially able to modify permissions of files referenced by symlinks in some circumstances.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
HAQM Linux 2 - Core | python | Not Affected | ||
HAQM Linux 1 | python26 | Not Affected | ||
HAQM Linux 1 | python27 | Not Affected | ||
HAQM Linux 2 - Core | python3 | 2024-05-09 | ALAS2-2024-2541 | Fixed |
HAQM Linux 2023 | python3.11 | 2024-05-09 | ALAS2023-2024-617 | Fixed |
HAQM Linux 2023 | python3.9 | 2024-05-09 | ALAS2023-2024-616 | Fixed |
HAQM Linux 1 | python34 | No Fix Planned | ||
HAQM Linux 1 | python35 | No Fix Planned | ||
HAQM Linux 1 | python36 | No Fix Planned | ||
HAQM Linux 1 | python38 | 2024-05-09 | ALAS-2024-1936 | Fixed |
HAQM Linux 2 - Python3.8 Extra | python38 | 2024-05-23 | ALAS2PYTHON3.8-2024-011 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
HAQM Linux | CVSSv3 | 7.8 | CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N |
NVD | CVSSv3 | 7.8 | CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N |