UBUNTU-CVE-2017-8921
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-8921
Summary:
Details: In FlightGear before 2017.2.1, the FGCommand interface allows overwriting any file the user has write access to, but not with arbitrary data: only with the contents of a FlightGear flightplan (XML). A resource such as a malicious third-party aircraft could exploit this to damage files belonging to the user. Both this issue and CVE-2016-9956 are directory traversal vulnerabilities in Autopilot/route_mgr.cxx - this one exists because of an incomplete fix for CVE-2016-9956.
References: https://ubuntu.com/security/CVE-2017-8921, https://sourceforge.net/p/flightgear/flightgear/ci/faf872e7f71ca14c567ac7080561fc785d8d2fd0/, https://www.cve.org/CVERecord?id=CVE-2017-8921
Affected packages
Package
Name: flightgear
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
