Bug ID 1167519
Summary VUL-1: CVE-2020-10870: zim: creates temporary directories with predictable names, enabling malicious users to prevent other users from being able to start Zim
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
URL https://smash.suse.de/issue/255622/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee luke@ljones.dev
Reporter wolfgang.frisch@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2020-10870

Zim through 0.72.1 creates temporary directories with predictable names. A
malicious user could predict and create Zim's temporary directories and prevent
other users from being able to start Zim, resulting in a denial of service.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-10870
https://github.com/zim-desktop-wiki/zim-desktop-wiki/issues/1028
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10870


You are receiving this mail because: