DEBIAN-CVE-2024-34490

Source
https://security-tracker.debian.org/tracker/CVE-2024-34490
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-34490.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2024-34490
Upstream
Published
2024-05-05T03:15:07Z
Modified
2026-09-15T09:03:18Z
Severity
  • 5.1 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
[none]
Details

In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local attacker who can create files in advance with these names. This affects, for example, plot2d.

References

Affected packages

Debian:12 / maxima

Package

Name
maxima
Purl
pkg:deb/debian/maxima?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.46.0-11
5.47.0-1
5.47.0-2
5.47.0-3
5.47.0-4
5.47.0-5
5.47.0-6
5.47.0-7
5.47.0-8
5.47.0-9
5.49.0-1~exp1
5.49.0+dsfg-1
5.49.0+dsfg-2
5.49.0+dsfg-3
5.49.0+dsfg-4~exp1
5.49.0+dsfg-4
5.49.0+dsfg-5~exp1
5.49.0+dsfg-5

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-34490.json"

Debian:13 / maxima

Package

Name
maxima
Purl
pkg:deb/debian/maxima?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.47.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-34490.json"

Debian:14 / maxima

Package

Name
maxima
Purl
pkg:deb/debian/maxima?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.47.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-34490.json"