vendor:
Cscope
by:
Gangstuck / Psirac
7.5
CVSS
HIGH
Insecure temporary file creation
CWE
Product Name: Cscope
Affected Version From:
Affected Version To: Cscope 15.5
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Cscope Symlink Vulnerability
Cscope creates temporary files in an insecure way, allowing attackers to create malicious symbolic links that Cscope will write to when executed by an unsuspecting user. This can lead to arbitrary file overwriting.
Mitigation:
It is recommended to update to a version of Cscope that addresses this vulnerability. Additionally, users should avoid executing Cscope on untrusted files.