CVE-2014-2893
The GetHTMLRunDir function in the scan-build utility in Clang 3.5 and earlier allows local users to obtain sensitive information or overwrite arbitrary files via a symlink attack on temporary directories with predictable names.
Ver en NVDSeveridad
N/A
EPSS
Probabilidad de explotación (próx. 30 días): 0.0006 (0.1%)
Percentil: 18.9%
EPSS: 2026-05-06
Afecta
opensuse:opensusellvm:clangDescripción técnica
The GetHTMLRunDir function in the scan-build utility in Clang 3.5 and earlier allows local users to obtain sensitive information or overwrite arbitrary files via a symlink attack on temporary directories with predictable names.
Publicada: 23/4/2014, 15:55:05
Última modificación: 6/5/2026, 22:30:45
Referencias
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00038.html
- http://www.openwall.com/lists/oss-security/2014/04/16/2
- http://www.openwall.com/lists/oss-security/2014/04/20/1
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744817
- http://lists.opensuse.org/opensuse-updates/2015-02/msg00038.html
- http://www.openwall.com/lists/oss-security/2014/04/16/2
- http://www.openwall.com/lists/oss-security/2014/04/20/1
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=744817