uu_install is vulnerable to Improper Handling of Path Equivalence
28
Low Risk
install --backup computes a backup path but does not check whether that path is the source file itself, unlike cp. When the backup name matches the source (for example install --backup=simple a~ a), the backup overwrites the source, the copy reads the overwritten file, the destination stays unchanged, and the command exits with success while the source data is destroyed. The fix adds a same file guard before creating the backup.
You are affected if you are using a version that falls within the vulnerable range and you use install --backup where the computed backup name can refer to the same file as the source.
uu_install is vulnerable to Improper Handling of Path Equivalence in versions 0.0.1 - 0.9.0.
Upgrade the uu_install library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.