cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.
2013-09-23T20:55:07.293
2025-04-11T00:51:21.963
Deferred
CVSSv2: 1.2 (LOW)
AV:L/AC:H/Au:N/C:N/I:P/A:N
1.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jeff_ortel | suds | 0.4 | Yes |
Operating System | opensuse | opensuse | 12.2 | Yes |
Operating System | opensuse | opensuse | 12.3 | Yes |
Operating System | redhat | enterprise_linux | 5 | Yes |
Operating System | redhat | enterprise_linux | 6.0 | Yes |