uu_mv is vulnerable to Improper Link Resolution Before File Access
52
Medium Risk
The mv utility's hardlink-preservation logic tracks source arguments by device and inode to decide which destination files should be linked together instead of copied independently. When a symlink is included among the source arguments, its target inode can be conflated with an unrelated hard-linked file, causing mv to link or overwrite the wrong destination content. The fix distinguishes symlink entries from their targets before building the hardlink map so unrelated files are no longer linked together.
You are affected if you are using a version that falls within the vulnerable range and you use mv to move multiple source paths that include a symlink alongside hard-linked regular files in the same command.
uu_mv is vulnerable to Improper Link Resolution Before File Access in versions 0.2.0 - 0.10.0.
Upgrade the uu_mv library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.