|
|
Log in / Subscribe / Register

npm: insecure temporary directory generation

Package(s):npm CVE #(s):CVE-2013-4116
Created:July 23, 2013 Updated:July 24, 2013
Description: From the Red Hat bugzilla:

An insecure temporary directory generation / use flaw was found in the way NPM, Node.js Package Manager, used to generate location of the temporary folder to be used for tarballs expansion. A local attacker could use this flaw to conduct symbolic link attacks, possibly leading to their ability to overwrite arbitrary system file reachable with the privileges of the user performing the NPM archive expansion.

Alerts:
Fedora FEDORA-2013-12908 node-gyp 2013-07-23
Fedora FEDORA-2013-11780 nodejs-callsite 2013-07-23
Fedora FEDORA-2013-11780 nodejs-glob 2013-07-23
Fedora FEDORA-2013-12908 npm 2013-07-23
Fedora FEDORA-2013-11780 npm 2013-07-23
Fedora FEDORA-2013-11780 nodejs-vows 2013-07-23
Fedora FEDORA-2013-11780 nodejs-tunnel-agent 2013-07-23
Fedora FEDORA-2013-11780 nodejs-tap 2013-07-23
Fedora FEDORA-2013-11780 nodejs-sntp 2013-07-23
Fedora FEDORA-2013-11780 nodejs-slide 2013-07-23
Fedora FEDORA-2013-12908 nodejs-sha 2013-07-23
Fedora FEDORA-2013-11780 nodejs-sha 2013-07-23
Fedora FEDORA-2013-12908 nodejs-semver 2013-07-23
Fedora FEDORA-2013-11780 nodejs-semver 2013-07-23
Fedora FEDORA-2013-11780 nodejs-rimraf 2013-07-23
Fedora FEDORA-2013-11780 nodejs-request 2013-07-23
Fedora FEDORA-2013-11780 nodejs-read-package-json 2013-07-23
Fedora FEDORA-2013-11780 nodejs-read-installed 2013-07-23
Fedora FEDORA-2013-11780 nodejs-oauth-sign 2013-07-23
Fedora FEDORA-2013-12908 nodejs-npmlog 2013-07-23
Fedora FEDORA-2013-11780 nodejs-npmlog 2013-07-23
Fedora FEDORA-2013-11780 nodejs-npmconf 2013-07-23
Fedora FEDORA-2013-11780 nodejs-npm-user-validate 2013-07-23
Fedora FEDORA-2013-12908 nodejs-npm-registry-client 2013-07-23
Fedora FEDORA-2013-11780 nodejs-npm-registry-client 2013-07-23
Fedora FEDORA-2013-11780 nodejs-normalize-package-data 2013-07-23
Fedora FEDORA-2013-12908 nodejs-lockfile 2013-07-23
Fedora FEDORA-2013-11780 nodejs-lockfile 2013-07-23
Fedora FEDORA-2013-11780 nodejs-json-stringify-safe 2013-07-23
Fedora FEDORA-2013-11780 nodejs-init-package-json 2013-07-23
Fedora FEDORA-2013-11780 nodejs-inherits1 2013-07-23
Fedora FEDORA-2013-11780 nodejs-inherits 2013-07-23
Fedora FEDORA-2013-11780 nodejs-http-signature 2013-07-23
Fedora FEDORA-2013-11780 nodejs-hoek 2013-07-23
Fedora FEDORA-2013-11780 nodejs-hawk 2013-07-23
Fedora FEDORA-2013-12908 nodejs-graceful-fs 2013-07-23
Fedora FEDORA-2013-11780 nodejs-graceful-fs 2013-07-23
Fedora FEDORA-2013-12908 nodejs-glob 2013-07-23
Fedora FEDORA-2013-11780 nodejs-github-url-from-git 2013-07-23
Fedora FEDORA-2013-11780 nodejs-fstream-npm 2013-07-23
Fedora FEDORA-2013-11780 nodejs-fstream-ignore 2013-07-23
Fedora FEDORA-2013-12908 nodejs-fstream 2013-07-23
Fedora FEDORA-2013-11780 nodejs-fstream 2013-07-23
Fedora FEDORA-2013-11780 nodejs-form-data 2013-07-23
Fedora FEDORA-2013-11780 nodejs-forever-agent 2013-07-23
Fedora FEDORA-2013-11780 nodejs-editor 2013-07-23
Fedora FEDORA-2013-11780 nodejs-ctype 2013-07-23
Fedora FEDORA-2013-11780 nodejs-cryptiles 2013-07-23
Fedora FEDORA-2013-11780 nodejs-couch-login 2013-07-23
Fedora FEDORA-2013-11780 nodejs-cookie-jar 2013-07-23
Fedora FEDORA-2013-11780 nodejs-config-chain 2013-07-23
Fedora FEDORA-2013-11780 nodejs-cmd-shim 2013-07-23
Fedora FEDORA-2013-11780 nodejs-child-process-close 2013-07-23
Fedora FEDORA-2013-11780 nodejs-boom 2013-07-23
Fedora FEDORA-2013-11780 nodejs-better-assert 2013-07-23
Fedora FEDORA-2013-11780 nodejs-aws-sign 2013-07-23
Fedora FEDORA-2013-11780 nodejs-asn1 2013-07-23
Fedora FEDORA-2013-11780 nodejs-ansi 2013-07-23
Fedora FEDORA-2013-12908 node-gyp 2013-07-23
Fedora FEDORA-2013-11780 node-gyp 2013-07-23

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds