Description
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-1290 | lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives. |
Github GHSA |
GHSA-v3jv-wrf4-5845 | Local Privilege Escalation in npm |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T16:30:49.923Z
Reserved: 2013-06-12T00:00:00.000Z
Link: CVE-2013-4116
No data.
Status : Deferred
Published: 2014-04-22T14:23:34.330
Modified: 2025-04-12T10:46:40.837
Link: CVE-2013-4116
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA