uu_sort is vulnerable to Insecure Temporary File
35
Low Risk
sort created its merge temporary files and, for options that copy the input, its output-copy file without restricting their permissions, leaving them readable by other local users while they hold sort data that may include sensitive input contents. Another user on a shared system could read the temporary file's contents before it is removed. The fix creates these files with private (0600) permissions.
You are affected if you are using a version that falls within the vulnerable range and other local users on the same system can read world-accessible temporary files.
uu_sort is vulnerable to Insecure Temporary File in versions 0.0.1 - 0.11.0.
Upgrade the uu_sort library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.