CVE-2024-34490

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-34490
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-34490.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-34490
Related
Published
2024-05-05T03:15:07Z
Modified
2024-10-29T22:47:37.903971Z
Summary
[none]
Details

In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local attacker who can create files in advance with these names. This affects, for example, plot2d.

References

Affected packages

Debian:11 / maxima

Package

Name
maxima
Purl
pkg:deb/debian/maxima?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.44.0-3
5.45.1-1
5.45.1-2
5.45.1-3
5.45.1-4
5.45.1-5
5.45.1-6
5.45.1-7
5.45.1-8
5.46.0-1
5.46.0-2
5.46.0-3
5.46.0-4
5.46.0-5
5.46.0-6
5.46.0-7
5.46.0-8
5.46.0-9
5.46.0-10
5.46.0-11
5.47.0-1
5.47.0-2
5.47.0-3
5.47.0-4
5.47.0-5

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / maxima

Package

Name
maxima
Purl
pkg:deb/debian/maxima?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.46.0-11
5.47.0-1
5.47.0-2
5.47.0-3
5.47.0-4
5.47.0-5

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / maxima

Package

Name
maxima
Purl
pkg:deb/debian/maxima?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.47.0-1

Affected versions

5.*

5.46.0-11

Ecosystem specific

{
    "urgency": "unimportant"
}