main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Cscope | — | Apply OS X security update 2007-007 | Dec 16, 2011 | Jan 10, 2005 |
| Debian | — | Upgrade cscope | Jul 30, 2024 | Jan 10, 2005 |
| Freebsd | — | Upgrade cscope | Dec 10, 2025 | Dec 7, 2004 |
| Gentoo Linux | — | Upgrade dev-util/cscope. | Oct 30, 2017 | Jan 10, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub