CVE-2015-4155: Low severity gnu parallel vulnerability
GNU Parallel before 20150422, when using (1) --pipe, (2) --tmux, (3) --cat, (4) --fifo, or (5) --compress, allows local users to write to arbitrary files via a symlink attack on a temporary file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4155?
CVE-2015-4155 is considered a medium severity vulnerability due to its potential for local users to perform unauthorized file writes.
How do I fix CVE-2015-4155?
To fix CVE-2015-4155, upgrade GNU Parallel to version 20150422 or later where the vulnerability has been addressed.
What systems are affected by CVE-2015-4155?
CVE-2015-4155 affects GNU Parallel versions prior to 20150422 when using specific command options including --pipe and --tmux.
Is CVE-2015-4155 a remote or local vulnerability?
CVE-2015-4155 is a local vulnerability that allows local users to exploit the symlink attack.
What are the risks associated with CVE-2015-4155?
The risks associated with CVE-2015-4155 include potential unauthorized modification or deletion of files on the affected system.