CRITICAL9.1
GHSA-r3r5-jhw6-4634
Insecure temporary file usage in SWHKD
Details
SWHKD 1.1.5 unsafely uses the /tmp/swhkd.sock pathname. There can be an information leak or denial of service.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/Simple-Wayland-HotKey-Daemon
Introduced in:
0Fixed in: 1.2.0Upgrade Simple-Wayland-HotKey-Daemon to 1.2.0 or newer (ecosystem crates.io).
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-27818[ADVISORY]
- https://github.com/waycrate/swhkd/commit/f70b99dd575fab79d8a942111a6980431f006818[WEB]
- https://github.com/waycrate/swhkd[PACKAGE]
- https://github.com/waycrate/swhkd/releases/tag/1.2.0[WEB]
- http://www.openwall.com/lists/oss-security/2022/04/14/1[WEB]