SageMath FlintQS 1.0 relies on pathnames under TMPDIR (typically world-writable), which (for example) allows a local user to overwrite files with the privileges of a different user (who is running FlintQS).
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2023-33034 | SageMath FlintQS 1.0 relies on pathnames under TMPDIR (typically world-writable), which (for example) allows a local user to overwrite files with the privileges of a different user (who is running FlintQS). | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Wed, 12 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-12T16:34:31.453Z
Reserved: 2023-04-06T00:00:00.000Z
Link: CVE-2023-29465
Updated: 2024-08-02T14:07:46.363Z
Status : Modified
Published: 2023-04-06T20:15:08.830
Modified: 2025-02-12T17:15:18.670
Link: CVE-2023-29465
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD