CVE-2023-23558

Source
https://cve.org/CVERecord?id=CVE-2023-23558
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-23558.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-23558
Published
2023-02-16T16:15:12.463Z
Modified
2026-04-10T04:55:36.961798Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

In Eternal Terminal 6.2.1, TelemetryService uses fixed paths in /tmp. For example, a local attacker can create /tmp/.sentry-native-etserver with mode 0777 before the etserver process is started. The attacker can choose to read sensitive information from that file, or modify the information in that file.

References

Affected packages

Git / github.com/mistertea/eternalterminal

Affected ranges

Type
GIT
Repo
https://github.com/mistertea/eternalterminal
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "6.2.1"
        }
    ]
}

Affected versions

et-v1.*
et-v1.1.1
et-v2.*
et-v2.0.0
et-v2.0.1
et-v2.0.2
et-v2.1.0
et-v3.*
et-v3.0.0
et-v3.0.1
et-v3.0.2
et-v3.0.4
et-v3.0.5
et-v3.0.6
et-v3.1.0
et-v3.1.1
et-v4.*
et-v4.0.1
et-v4.0.2
et-v4.0.3
et-v4.0.4
et-v4.0.5
et-v4.1.0
et-v4.1.1
et-v4.1.2
et-v4.2.0
et-v4.2.1
et-v5.*
et-v5.0.0
et-v5.0.1
et-v5.0.2
et-v5.0.3
et-v5.0.4
et-v5.0.5
et-v5.0.6
et-v5.0.7
et-v5.1.0
et-v6.*
et-v6.0.1
et-v6.0.2
et-v6.1.11
et-v6.2.0
et-v6.2.1
v1.*
v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-23558.json"