CVE-2022-48682

In deletefiles in FDUPES before 2.2.0, a TOCTOU race condition allows arbitrary file deletion via a symlink.
Configurations

No configuration.

History

21 Nov 2024, 07:33

Type Values Removed Values Added
References () https://bugzilla.suse.com/show_bug.cgi?id=1200381 - () https://bugzilla.suse.com/show_bug.cgi?id=1200381 -
References () https://github.com/adrianlopezroche/fdupes/blob/4b6bcde1b3eb1cebe87cd30814f7d6cf4ee46e95/fdupes.c - () https://github.com/adrianlopezroche/fdupes/blob/4b6bcde1b3eb1cebe87cd30814f7d6cf4ee46e95/fdupes.c -
References () https://github.com/adrianlopezroche/fdupes/commit/85680897148f1ac33b55418e00334116e419717f - () https://github.com/adrianlopezroche/fdupes/commit/85680897148f1ac33b55418e00334116e419717f -
References () https://github.com/adrianlopezroche/fdupes/compare/v2.1.2...v2.2.0 - () https://github.com/adrianlopezroche/fdupes/compare/v2.1.2...v2.2.0 -

27 Oct 2024, 22:35

Type Values Removed Values Added
Summary
  • (es) En los archivos de eliminación en FDUPES anteriores a 2.2.0, una condición de ejecución TOCTOU permite la eliminación arbitraria de archivos a través de un enlace simbólico.
CWE CWE-367

26 Apr 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-26 01:15

Updated : 2024-11-21 07:33


NVD link : CVE-2022-48682

Mitre link : CVE-2022-48682

CVE.ORG link : CVE-2022-48682


JSON object : View

Products Affected

No product.

CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition