Vulnerability Description
Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory named on a require line.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atom | Electron | <= 0.33.4 |
References
- http://jvn.jp/en/jp/JVN00324715/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000054Vendor Advisory
- https://github.com/electron/electron/commit/9a2e2b365d061ec10cd861391fd5b1344af7
- https://github.com/electron/electron/pull/2976
- http://jvn.jp/en/jp/JVN00324715/index.htmlVendor Advisory
- http://jvndb.jvn.jp/jvndb/JVNDB-2016-000054Vendor Advisory
- https://github.com/electron/electron/commit/9a2e2b365d061ec10cd861391fd5b1344af7
- https://github.com/electron/electron/pull/2976
FAQ
What is CVE-2016-1202?
CVE-2016-1202 is a vulnerability with a CVSS score of 7.8 (HIGH). Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory named on a require line.
How severe is CVE-2016-1202?
CVE-2016-1202 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-1202?
Check the references section above for vendor advisories and patch information. Affected products include: Atom Electron.