Impact
The vulnerability is an external control of file name or path supplied to pardus‑image‑writer. The missing validation allows an attacker to specify arbitrary paths, which the application uses to write directly to any block device. This can erase or corrupt critical data and effectively remove important client functionality. The weakness maps to CWE‑73, and while it primarily threatens the integrity and availability of underlying storage, confidentiality is not directly affected.
Affected Systems
The flaw affects TÜBİTAK BİLGEM Software Technologies Research Institute's pardus‑image‑writer prior to version 0.9.0. Users running these earlier releases are vulnerable to the unchecked write operation.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability falls into the medium‑to‑high severity range. The EPSS score is < 1 % and the vulnerability is not listed in CISA's KEV catalog, indicating limited known exploitation. The likely attack path requires an attacker who can provide or influence the file name or path argument—either through user input or a compromised local account—so exploitation is inferred to be local or via command‑line interaction. Because the attacker can overwrite arbitrary block devices, immediate remedial action is recommended to mitigate potential data loss.
OpenCVE Enrichment