uu_rm is vulnerable to Race Condition (TOCTOU)
70
High Risk
Recursive descent opens subdirectory entries without following symlinks, but the top level operand is still opened by path after a separate metadata check, with no inode re-verification. A local user who controls the operand or its parent directory can swap a directory for a symlink between the check and the open, so deletion reaches outside the intended subtree. The fix re-verifies the opened operand against the checked inode.
You are affected if you are using a version that falls within the vulnerable range and you run recursive rm on an operand whose path or parent directory another local user can modify concurrently.
uu_rm is vulnerable to Race Condition (TOCTOU) in versions 0.0.1 - 0.10.0.
Upgrade the uu_rm library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.