World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this directory.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tmate-ssh-server | Tmate | * | 2.3.0 (including) |
Tmate-ssh-server | Ubuntu | devel | * |
Tmate-ssh-server | Ubuntu | esm-apps/jammy | * |
Tmate-ssh-server | Ubuntu | esm-apps/noble | * |
Tmate-ssh-server | Ubuntu | hirsute | * |
Tmate-ssh-server | Ubuntu | impish | * |
Tmate-ssh-server | Ubuntu | jammy | * |
Tmate-ssh-server | Ubuntu | kinetic | * |
Tmate-ssh-server | Ubuntu | lunar | * |
Tmate-ssh-server | Ubuntu | mantic | * |
Tmate-ssh-server | Ubuntu | noble | * |
Tmate-ssh-server | Ubuntu | oracular | * |
Tmate-ssh-server | Ubuntu | trusty | * |
Tmate-ssh-server | Ubuntu | xenial | * |