First published: Tue Jun 02 2015(Updated: )
GNU Parallel before 20150422, when using (1) --pipe, (2) --tmux, (3) --cat, (4) --fifo, or (5) --compress, allows local users to write to arbitrary files via a symlink attack on a temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Parallel | <=20150322 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4155 is considered a medium severity vulnerability due to its potential for local users to perform unauthorized file writes.
To fix CVE-2015-4155, upgrade GNU Parallel to version 20150422 or later where the vulnerability has been addressed.
CVE-2015-4155 affects GNU Parallel versions prior to 20150422 when using specific command options including --pipe and --tmux.
CVE-2015-4155 is a local vulnerability that allows local users to exploit the symlink attack.
The risks associated with CVE-2015-4155 include potential unauthorized modification or deletion of files on the affected system.