GNU Parallel before 20150522 (Nepal), when using (1) --cat or (2) --fifo with --sshlogin, allows local users to write to arbitrary files via a symlink attack on a temporary file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2015-06-02T14:00:00

Updated: 2024-08-06T06:04:02.813Z

Reserved: 2015-06-02T00:00:00

Link: CVE-2015-4156

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2015-06-02T14:59:16.333

Modified: 2018-10-30T16:27:35.843

Link: CVE-2015-4156

cve-icon Redhat

No data.