[oss-security] 20220414 Multiple vulnerabilities in swhkd hotkey helper for Waylandmailing list
http://www.openwall.com/lists/oss-security/2022/04/14/1 CVE-2022-27815
HIGH
Insecure Temporary File in SWHKD
Record summary
CVE-2022-27815 has a selected CVSS score of 7.8 (high).
Description
SWHKD 1.1.5 unsafely uses the /tmp/swhkd.pid pathname. There can be an information leak or denial of service.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Simple-Wayland-HotKey-DaemonBrowse crates.io / Simple-Wayland-HotKey-Daemon | GitHub Advisory | Before 1.2.0 · Fixed in 1.2.0 | affected |
References
6github.com
https://github.com/waycrate/swhkd github.com
https://github.com/waycrate/swhkd/commit/e661a4940df78fbb7b52c622ac4ae6a3a7f7d8aa github.com
https://github.com/waycrate/swhkd/releases github.com
https://github.com/waycrate/swhkd/releases/tag/1.2.0 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-27815