In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local attacker who can create files in advance with these names. This affects, for example, plot2d.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-02T02:51:11.574Z

Reserved: 2024-05-05T00:00:00

Link: CVE-2024-34490

cve-icon Vulnrichment

Updated: 2024-08-02T02:51:11.574Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-05T03:15:07.293

Modified: 2024-11-21T09:18:49.207

Link: CVE-2024-34490

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.