CVE-2018-14043
Dashboard / Vulnerabilities / CVE-2018-14043
CVE-2018-14043
Published: 13 Jul 2018Last Modified: 22 May 2024
Summary:
Details: mstdlib (aka the M Standard Library for C) 1.2.0 has incorrect file access control in situations where M_fs_perms_can_access attempts to delete an existing file (that lacks public read/write access) during a copy operation, related to fs/m_fs.c and fs/m_fs_path.c. An attacker could create the file and then would have access to the data.
References: https://github.com/Monetra/mstdlib/commit/db124b8f607dd0a40a9aef2d4d468fad433522a7, https://github.com/Monetra/mstdlib/issues/2
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
