3.5 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
Activity log
- Created suggestion
wormhole receive, with --output pointing at an existing directory can be path-traversed
Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. Prior to 0.24.0, there is a path traversal when a receiver who specifies "--output <dir>" where that output directory currently exists (as a directory). This vulnerability is fixed in 0.24.0.
References
Affected products
- ==< 0.24.0
Matching in nixpkgs
pkgs.wormhole-rs
Rust implementation of Magic Wormhole, with new features and enhancements
pkgs.magic-wormhole
Securely transfer data between computers
pkgs.magic-wormhole-rs
Rust implementation of Magic Wormhole, with new features and enhancements
pkgs.python312Packages.magic-wormhole
Securely transfer data between computers
pkgs.python313Packages.magic-wormhole
Securely transfer data between computers
pkgs.python314Packages.magic-wormhole
Securely transfer data between computers
pkgs.python312Packages.magic-wormhole-transit-relay
Transit Relay server for Magic-Wormhole
pkgs.python313Packages.magic-wormhole-transit-relay
Transit Relay server for Magic-Wormhole
pkgs.python314Packages.magic-wormhole-transit-relay
Transit Relay server for Magic-Wormhole
pkgs.python312Packages.magic-wormhole-mailbox-server
Securely transfer data between computers
pkgs.python313Packages.magic-wormhole-mailbox-server
Securely transfer data between computers
pkgs.python314Packages.magic-wormhole-mailbox-server
Securely transfer data between computers
Package maintainers
-
@mjoerg Martin Joerg <martin.joerg@gmail.com>
-
@piegamesde piegames <nix@piegames.de>
-
@zeri42 zeri