CVE-2013-1809

HIGH

Gambas < 3.4.0 - Symlink Attack via Insecure Temporary Directory Creation

Title source: llm
STIX 2.1

Description

Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories.

References (6)

Core 6
Core References
Third Party Advisory x_refsource_misc
https://security-tracker.debian.org/tracker/CVE-2013-1809
Issue Tracking, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-1809
Not Applicable, Third Party Advisory x_refsource_misc
https://access.redhat.com/security/cve/cve-2013-1809
Mailing List, Third Party Advisory x_refsource_misc
http://www.openwall.com/lists/oss-security/2013/03/03/4
Issue Tracking, Third Party Advisory x_refsource_misc
https://code.google.com/archive/p/gambas/issues/365
Patch, Third Party Advisory x_refsource_confirm
https://sourceforge.net/p/gambas/code/5438/

Scores

CVSS v3 7.5
EPSS 0.0201
EPSS Percentile 78.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-59
Status published
Products (4)
debian/debian_linux 8.0
debian/debian_linux 9.0
debian/debian_linux 10.0
gambas_project/gambas < 3.4.0
Published Nov 07, 2019
Tracked Since Feb 18, 2026