uu_chmod is vulnerable to Link Following
73
High Risk
The --preserve-root guard in chmod checks only the top level operands and is not re-checked during recursive descent. A symlink to / reached while recursing applies permission changes to the real root filesystem, defeating the guard. A privileged chmod -R -L --preserve-root run over an untrusted tree can reach that symlink. The fix no longer follows symlinks during descent so recursion does not resolve a swapped symlink to /.
You are affected if you are using a version that falls within the vulnerable range and you run chmod -R -L --preserve-root over a directory tree an untrusted local user can modify.
uu_chmod is vulnerable to Link Following in versions 0.0.1 - 0.9.0.
Upgrade the uu_chmod library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.