Intel

AIKIDO-2024-10164

cog is vulnerable to Race Condition

Race Condition Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 3, 2024

55

Medium Risk

This Affects:

pythoncog
0.5.0 - 0.9.11
Fixed in 0.9.12
Are you affected? Scan for Free

TL;DR

Affected versions of this package experience a race condition that may lead to data corruption.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

cog is vulnerable to Race Condition in versions 0.5.0 - 0.9.11.

How to fix this

Upgrade the cog library to the patch version.