Zim through 0.72.1 creates temporary directories with predictable names. A malicious user could predict and create Zims temporary directories and prevent other users from being able to start Zim, resulting in a denial of service.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zim | Zim-wiki | * | 0.72.1 (including) |
Zim | Ubuntu | bionic | * |
Zim | Ubuntu | eoan | * |
Zim | Ubuntu | esm-apps/bionic | * |
Zim | Ubuntu | esm-apps/focal | * |
Zim | Ubuntu | esm-apps/xenial | * |
Zim | Ubuntu | focal | * |
Zim | Ubuntu | trusty | * |
Zim | Ubuntu | upstream | * |
Zim | Ubuntu | xenial | * |