uu_cp is vulnerable to Link Following
50
Medium Risk
During a recursive copy, uu_cp treats a destination entry that is a symlink to a directory as an existing directory and writes the source subtree through it. A local user who can plant such a symlink in the destination can cause the copy to write files outside the intended tree. The fix treats a destination symlink as a non-directory and no longer follows it.
You are affected if you are using a version that falls within the vulnerable range and you perform a recursive copy into a destination directory whose entries can be created or influenced by another local user.
uu_cp is vulnerable to Link Following in versions 0.0.1 - 0.9.0.
Upgrade the uu_cp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant