Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-34952 | Libarchive through 3.6.2 can cause directories to have world-writable permissions. The umask() call inside archive_write_disk_posix.c changes the umask of the whole process for a very short period of time; a race condition with another thread can lead to a permanent umask 0 setting. Such a race condition could lead to implicit directory creation with permissions 0777 (without the sticky bit), which means that any low-privileged local user can delete and rename files inside those directories. |
Tue, 14 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-01-14T17:07:29.493Z
Reserved: 2023-04-12T00:00:00.000Z
Link: CVE-2023-30571
Updated: 2024-08-02T14:28:51.957Z
Status : Modified
Published: 2023-05-29T20:15:09.513
Modified: 2025-01-14T17:15:11.673
Link: CVE-2023-30571
OpenCVE Enrichment
No data.
EUVD