In HTSlib 1.8, a race condition in cram/cram_io.c might allow local users to overwrite arbitrary files via a symlink attack.
References
Link Resource
https://github.com/samtools/htslib/issues/736 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-07-17T02:00:00

Updated: 2018-07-17T02:57:01

Reserved: 2018-07-16T00:00:00


Link: CVE-2018-14329

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-07-17T02:29:00.220

Modified: 2019-09-18T14:21:40.190


Link: CVE-2018-14329

JSON object: View

cve-icon Redhat Information

No data.