Vulnerability Description
In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Stellarium | Stellarium | <= 1.2 |
Related Weaknesses (CWE)
References
- https://github.com/Stellarium/stellarium/commit/1261f74dc4aa6bbd01ab514343424097Patch
- https://github.com/Stellarium/stellarium/commit/787a894897b7872ae96e6f5804a18221Patch
- https://github.com/Stellarium/stellarium/commit/eba61df3b38605befcb43687a4c0a159Patch
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://github.com/Stellarium/stellarium/commit/1261f74dc4aa6bbd01ab514343424097Patch
- https://github.com/Stellarium/stellarium/commit/787a894897b7872ae96e6f5804a18221Patch
- https://github.com/Stellarium/stellarium/commit/eba61df3b38605befcb43687a4c0a159Patch
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2023-28371?
CVE-2023-28371 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal.
How severe is CVE-2023-28371?
CVE-2023-28371 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-28371?
Check the references section above for vendor advisories and patch information. Affected products include: Stellarium Stellarium.