uucore is vulnerable to Link Following
28
Low Risk
The Linux fast path shared by recursive chown and chgrp uses a path test that follows symlinks again, which contradicts default -P handling that does not dereference them. A command line symlink to a directory is opened following the link, so ownership or group changes apply to the target directory instead of the symlink. The fix branches on the already obtained metadata instead of re-resolving the path.
You are affected if you are using a version that falls within the vulnerable range and you run recursive chown or chgrp on a command line symlink to a directory under default -P handling.
uucore is vulnerable to Link Following in versions 0.0.1 - 0.9.0.
Upgrade the uucore library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.