First published: Tue Jan 28 2025(Updated: )
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
SimGear |
Upgrade to FlightGear version 2020.3.20 or 2024.1.1.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0781 is rated as a critical severity vulnerability due to its ability to bypass sandboxing and allow arbitrary file writing.
To fix CVE-2025-0781, update to the latest version of SimGear where the vulnerability has been addressed.
CVE-2025-0781 affects SimGear, particularly versions that allow Nasal script execution.
With CVE-2025-0781, attackers can bypass sandbox restrictions and write to any file path the user has permission to modify.
Mitigation for CVE-2025-0781 involves applying patches promptly and restricting script execution where possible.