Arbitrary File Overwrite Affecting github.com/github/hub Open this link in a new tab package, versions <1.12.1
Attack Complexity
Low
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications-
snyk-id
SNYK-GOLANG-GITHUBCOMGITHUBHUB-50036
-
published
13 Apr 2014
-
disclosed
13 Apr 2014
-
credit
Unknown
Introduced: 13 Apr 2014
CVE-2014-0177 Open this link in a new tabOverview
Affected version of github.com/github/hub
are vulnerable to Arbitrary File Overwrite.
The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file.