In deletefiles in FDUPES before 2.2.0, a TOCTOU race condition allows arbitrary file deletion via a symlink.
The product checks the state of a resource before using that resource, but the resource’s state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Fdupes | Ubuntu | esm-apps/bionic | * |
Fdupes | Ubuntu | esm-apps/focal | * |
Fdupes | Ubuntu | esm-apps/xenial | * |
Fdupes | Ubuntu | focal | * |
Fdupes | Ubuntu | jammy | * |
Fdupes | Ubuntu | upstream | * |