uu_head is vulnerable to Race Condition (TOCTOU)
22
Low Risk
head uses a separate metadata call on a target path to decide header printing and directory handling, then opens the file in a second step. A local user can swap the path between the check and the open, so head reads a different file than the one from the metadata call. The fix opens the file first and reads metadata from the open descriptor so both operations refer to the same inode.
You are affected if you are using a version that falls within the vulnerable range and you run head on paths a local user can replace.
uu_head is vulnerable to Race Condition (TOCTOU) in versions 0.0.1 - 0.9.0.
Upgrade the uu_head library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.