Vulnerability Description
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Node Packaged Modules Project | Node Packaged Modules | < 1.3.3 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2013/07/10/17Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/07/11/9Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/61083Third Party AdvisoryVDB Entry
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=715325Issue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=983917Issue TrackingThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87141Third Party AdvisoryVDB Entry
- https://github.com/npm/npm/commit/f4d31693PatchThird Party Advisory
- https://github.com/npm/npm/issues/3635Third Party Advisory
- http://www.openwall.com/lists/oss-security/2013/07/10/17Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/07/11/9Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/61083Third Party AdvisoryVDB Entry
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=715325Issue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=983917Issue TrackingThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87141Third Party AdvisoryVDB Entry
- https://github.com/npm/npm/commit/f4d31693PatchThird Party Advisory
FAQ
What is CVE-2013-4116?
CVE-2013-4116 is a vulnerability with a CVSS score of 3.3 (LOW). lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking ar...
How severe is CVE-2013-4116?
CVE-2013-4116 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-4116?
Check the references section above for vendor advisories and patch information. Affected products include: Node Packaged Modules Project Node Packaged Modules.