CVE Vulnerabilities

CVE-2021-39828

Creation of Temporary File in Directory with Insecure Permissions

Published: Sep 27, 2021 | Modified: Oct 01, 2021
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by a privilege escalation vulnerability in the Digital Editions installer. An authenticated attacker could leverage this vulnerability to escalate privileges. User interaction is required before product installation to abuse this vulnerability.

Weakness

The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file’s existence or otherwise access that file.

Affected Software

Name Vendor Start Version End Version
Digital_editions Adobe * 4.5.11.187646 (including)

Potential Mitigations

References