On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges.



By tampering with such file, a malicious local user in the system may be able to trigger arbitrary code execution with root privileges.
Fixes

Solution

Upgrade to v1.6.0 or later.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2024-08-02T08:14:25.124Z

Reserved: 2023-11-02T15:59:49.270Z

Link: CVE-2023-5936

cve-icon Vulnrichment

Updated: 2024-08-02T08:14:25.124Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-15T16:15:09.350

Modified: 2024-11-21T08:42:48.817

Link: CVE-2023-5936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.