Privileges Escalation Affecting pastescript package, versions [,1.7.5)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
4.91% (93rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-PASTESCRIPT-40091
  • published8 Feb 2012
  • disclosed8 Feb 2012
  • creditClay Gerrard

Introduced: 8 Feb 2012

CVE-2012-0878  (opens in a new tab)
CWE-264  (opens in a new tab)

Overview

pastescript is a pluggable command-line frontend, including commands to setup package file layouts Paste Script 1.7.5 and earlier does not properly set group memberships during execution with root privileges, which might allow remote attackers to bypass intended file-access restrictions by leveraging a web application that uses the local filesystem.

CVSS Scores

version 3.1