World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this directory.
[
{
"signature_type": "Function",
"target": {
"file": "tmate-main.c",
"function": "main"
},
"deprecated": false,
"source": "https://github.com/tmate-io/tmate-ssh-server/commit/1c020d1f5ca462f5b150b46a027aaa1bbe3c9596",
"id": "CVE-2021-44512-b4fa32fc",
"signature_version": "v1",
"digest": {
"function_hash": "316549956568796934807268776517522169863",
"length": 1691.0
}
},
{
"signature_type": "Line",
"target": {
"file": "tmate-main.c"
},
"deprecated": false,
"source": "https://github.com/tmate-io/tmate-ssh-server/commit/1c020d1f5ca462f5b150b46a027aaa1bbe3c9596",
"id": "CVE-2021-44512-b5bc6fcf",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"80207026068406672254999970398237947067",
"173423011980781517915885963108284035295",
"306643597840451258993558618338827943855",
"83505621522273002792930872341900023227",
"136076212102058759837031658291138517335",
"310518699917455409064642457929409388070",
"176290184624510983014086540170709540683",
"152451022566174787559069177947798513311",
"72876143243196640920421934159468931924",
"184047213435252695687185796533395052901",
"21004837053619300072504869666184033231",
"211129072721360576409360749973093728649",
"229693977904854031536266170358141525484",
"152841598158707753820788575096253228192"
]
}
}
]