Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.170813
Category:General
Title:Python Symlink Dereference Vulnerability (Mar 2024) - Mac OS X
Summary:Python is prone to a symlink dereference vulnerability.
Description:Summary:
Python is prone to a symlink dereference vulnerability.

Vulnerability Insight:
The tempfile.TemporaryDirectory class would dereference symlinks
during cleanup of permissions-related errors. This means users which can run privileged programs
are potentially able to modify permissions of files referenced by symlinks in some
circumstances.

Affected Software/OS:
Python prior to version 3.8.19, 3.9.x prior to 3.9.19, 3.10.x
prior to 3.10.14, 3.11.x prior to 3.11.8 and 3.12.x prior to 3.12.1.

Solution:
Update to version 3.8.19, 3.9.19, 3.10.14, 3.11.8, 3.12.1
or later.

CVSS Score:
5.6

CVSS Vector:
AV:L/AC:H/Au:N/C:C/I:C/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2023-6597
http://www.openwall.com/lists/oss-security/2024/03/20/5
https://github.com/python/cpython/commit/02a9259c717738dfe6b463c44d7e17f2b6d2cb3a
https://github.com/python/cpython/commit/5585334d772b253a01a6730e8202ffb1607c3d25
https://github.com/python/cpython/commit/6ceb8aeda504b079fef7a57b8d81472f15cdd9a5
https://github.com/python/cpython/commit/81c16cd94ec38d61aa478b9a452436dc3b1b524d
https://github.com/python/cpython/commit/8eaeefe49d179ca4908d052745e3bb8b6f238f82
https://github.com/python/cpython/commit/d54e22a669ae6e987199bb5d2c69bb5a46b0083b
https://github.com/python/cpython/issues/91133
https://lists.debian.org/debian-lts-announce/2024/03/msg00025.html
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3IGRX54M7RNCQOXVQO5KQKTGWCOABIM/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5VHWS52HGD743C47UMCSAK2A773M2YE/
https://mail.python.org/archives/list/security-announce@python.org/thread/Q5C6ATFC67K53XFV4KE45325S7NS62LD/
CopyrightCopyright (C) 2024 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.