In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local attacker who can create files in advance with these names. This affects, for example, plot2d.
Creating and using insecure temporary files can leave application and system data vulnerable to attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Maxima | Ubuntu | mantic | * |