VDB
Sign up
HIGH7.8

GHSA-pp74-39w2-v4w9

Permissions bypass in pleaser

Details

pleaseedit in pleaser before 0.4.0 uses predictable temporary filenames in /tmp and the target directory. This allows a local attacker to gain full root privileges by staging a symlink attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/pleaser
Introduced in: 0Fixed in: 0.4.0

Upgrade pleaser to 0.4.0 or newer (ecosystem crates.io).

References