Permalink
CVE-2025-13044
6.2 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): HIGH
- Availability impact (A): NONE
Multiple Vulnerabilities in IBM Concert Software
IBM Concert 1.0.0 through 2.2.0 creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
References
Affected products
Concert
- =<2.2.0
Matching in nixpkgs
pkgs.coqPackages.ConCert
A framework for smart contract verification in Rocq
Package maintainers
-
@4ever2 Eske Nielsen <eske@cs.au.dk>