hugin, as used on various operating systems including SUSE openSUSE 10.2 and 10.3, allows local users to overwrite arbitrary files via a symlink attack on the hugin_debug_optim_results.txt temporary file.
CVSS Details
- CVSS 3.1 Base Score: 4.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade hugin | Jul 30, 2024 | Oct 14, 2007 |
| Gentoo Linux | — | Upgrade media-gfx/hugin. | Oct 30, 2017 | Oct 14, 2007 |
| Suse | — | Upgrade suse-releaseUpgrade hugin | Feb 17, 2015 | Oct 14, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub