CVE-2014-0177: Medium severity GitHub Hub vulnerability
The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file.
Other sources
The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0177?
CVE-2014-0177 is considered a security vulnerability that can allow local users to overwrite arbitrary files via a symlink attack.
How do I fix CVE-2014-0177?
To remediate CVE-2014-0177, upgrade the hub package to version 1.12.1 or later.
What software is affected by CVE-2014-0177?
CVE-2014-0177 affects hub versions prior to 1.12.1 from both rubygems and GitHub.
Can CVE-2014-0177 lead to unauthorized access?
Yes, CVE-2014-0177 can potentially allow local users to gain unauthorized access to overwrite sensitive files.
Is CVE-2014-0177 a remote vulnerability?
No, CVE-2014-0177 is a local vulnerability that requires local user access to exploit.