CVE Vulnerabilities

CVE-2023-6597

Published: Mar 19, 2024 | Modified: Jun 10, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.8 IMPORTANT
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Ubuntu
MEDIUM

An issue was found in the CPython tempfile.TemporaryDirectory class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior.

The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are potentially able to modify permissions of files referenced by symlinks in some circumstances.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 8 RedHat python3-0:3.6.8-62.el8_10 *
Red Hat Enterprise Linux 8 RedHat python39:3.9-8100020240516111311.d47b87a4 *
Red Hat Enterprise Linux 8 RedHat python39-devel:3.9-8100020240516111311.d47b87a4 *
Red Hat Enterprise Linux 8 RedHat python3.11-0:3.11.9-1.el8_10 *
Red Hat Enterprise Linux 8 RedHat python3-0:3.6.8-62.el8_10 *
Red Hat Enterprise Linux 8.2 Advanced Update Support RedHat python3-0:3.6.8-24.el8_2.3 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat python3-0:3.6.8-39.el8_4.5 *
Red Hat Enterprise Linux 8.4 Telecommunications Update Service RedHat python3-0:3.6.8-39.el8_4.5 *
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions RedHat python3-0:3.6.8-39.el8_4.5 *
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support RedHat python3-0:3.6.8-47.el8_6.6 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat python3-0:3.6.8-47.el8_6.6 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat python3-0:3.6.8-47.el8_6.6 *
Red Hat Enterprise Linux 8.8 Extended Update Support RedHat python3-0:3.6.8-51.el8_8.6 *
Red Hat Enterprise Linux 8.8 Extended Update Support RedHat python3.11-0:3.11.2-2.el8_8.3 *
Red Hat Enterprise Linux 9 RedHat python3.11-0:3.11.7-1.el9_4.1 *
Red Hat Enterprise Linux 9 RedHat python3.9-0:3.9.18-3.el9_4.1 *
Red Hat Enterprise Linux 9 RedHat python3.9-0:3.9.18-3.el9_4.1 *
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions RedHat python3.9-0:3.9.10-4.el9_0.4 *
Red Hat Enterprise Linux 9.2 Extended Update Support RedHat python3.11-0:3.11.2-2.el9_2.4 *
Red Hat Enterprise Linux 9.2 Extended Update Support RedHat python3.9-0:3.9.16-1.el9_2.5 *
Service Interconnect 1.4 for RHEL 9 RedHat service-interconnect/skupper-router-rhel9:2.4.3-5 *
Service Interconnect 1 for RHEL 9 RedHat service-interconnect/skupper-router-rhel9:2.5.3-2 *
Python3.10 Ubuntu jammy *
Python3.10 Ubuntu upstream *
Python3.11 Ubuntu mantic *
Python3.12 Ubuntu mantic *
Python3.5 Ubuntu esm-infra/xenial *
Python3.7 Ubuntu esm-apps/bionic *
Python3.8 Ubuntu esm-apps/bionic *
Python3.8 Ubuntu focal *
Python3.8 Ubuntu upstream *
Python3.9 Ubuntu esm-apps/focal *
Python3.9 Ubuntu upstream *

References