eroaster before 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file that is used as a lockfile.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Eroaster | Eroaster | 2.0.0 (including) | 2.0.0 (including) |
Eroaster | Eroaster | 2.1.0 (including) | 2.1.0 (including) |
Eroaster | Eroaster | 2.2.0 (including) | 2.2.0 (including) |