World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this directory.
[ { "source": "https://github.com/tmate-io/tmate-ssh-server/commit/1c020d1f5ca462f5b150b46a027aaa1bbe3c9596", "target": { "function": "main", "file": "tmate-main.c" }, "id": "CVE-2021-44512-b4fa32fc", "deprecated": false, "signature_version": "v1", "digest": { "function_hash": "316549956568796934807268776517522169863", "length": 1691.0 }, "signature_type": "Function" }, { "source": "https://github.com/tmate-io/tmate-ssh-server/commit/1c020d1f5ca462f5b150b46a027aaa1bbe3c9596", "target": { "file": "tmate-main.c" }, "id": "CVE-2021-44512-b5bc6fcf", "deprecated": false, "signature_version": "v1", "digest": { "line_hashes": [ "80207026068406672254999970398237947067", "173423011980781517915885963108284035295", "306643597840451258993558618338827943855", "83505621522273002792930872341900023227", "136076212102058759837031658291138517335", "310518699917455409064642457929409388070", "176290184624510983014086540170709540683", "152451022566174787559069177947798513311", "72876143243196640920421934159468931924", "184047213435252695687185796533395052901", "21004837053619300072504869666184033231", "211129072721360576409360749973093728649", "229693977904854031536266170358141525484", "152841598158707753820788575096253228192" ], "threshold": 0.9 }, "signature_type": "Line" } ]