Impact
The flaw stems from improper link resolution before file access in TUBITAK BILGEM's Pardus About. An attacker can create a symbolic link that points outside the intended directory, enabling the application to read or potentially write files it should not access. This vulnerability, identified as CWE‑59, can lead to the disclosure of confidential data and may allow modification of system files if the attack succeeds.
Affected Systems
The affected software is Pardus About from TUBITAK BILGEM Software Technologies Research Institute. All installations running a version earlier than 1.2.2 are vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is < 1%, indicating a very low probability of exploitation at this time. The issue is not listed in CISA's KEV catalog. The flaw can be exploited by crafting a malicious symbolic link that points to restricted files; while the description does not explicitly state the required conditions, it is inferred that the attack vector is primarily local or requires the attacker to create the link on a writable path used by the application.
OpenCVE Enrichment