In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the information in that file.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2023-02-16T00:00:00
Updated: 2024-08-02T10:35:33.355Z
Reserved: 2023-01-13T00:00:00
Link: CVE-2023-23558
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-02-16T16:15:12.463
Modified: 2024-11-21T07:46:25.087
Link: CVE-2023-23558
Redhat
No data.