CVE Vulnerabilities

CVE-2013-4235

Time-of-check Time-of-use (TOCTOU) Race Condition

Published: Dec 03, 2019 | Modified: Nov 21, 2024
CVSS 3.x
4.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
3.3 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
4.4 LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
Ubuntu
LOW

shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees

Weakness

The product checks the state of a resource before using that resource, but the resource’s state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.

Affected Software

Name Vendor Start Version End Version
Shadow Debian - (including) - (including)
Shadow Ubuntu artful *
Shadow Ubuntu bionic *
Shadow Ubuntu cosmic *
Shadow Ubuntu disco *
Shadow Ubuntu eoan *
Shadow Ubuntu esm-infra-legacy/trusty *
Shadow Ubuntu esm-infra/bionic *
Shadow Ubuntu esm-infra/xenial *
Shadow Ubuntu focal *
Shadow Ubuntu groovy *
Shadow Ubuntu hirsute *
Shadow Ubuntu impish *
Shadow Ubuntu jammy *
Shadow Ubuntu kinetic *
Shadow Ubuntu lucid *
Shadow Ubuntu precise *
Shadow Ubuntu precise/esm *
Shadow Ubuntu trusty *
Shadow Ubuntu trusty/esm *
Shadow Ubuntu upstream *
Shadow Ubuntu utopic *
Shadow Ubuntu vivid *
Shadow Ubuntu vivid/stable-phone-overlay *
Shadow Ubuntu vivid/ubuntu-core *
Shadow Ubuntu wily *
Shadow Ubuntu xenial *
Shadow Ubuntu yakkety *
Shadow Ubuntu zesty *

Potential Mitigations

References