UBUNTU-CVE-2024-34490

Source
https://ubuntu.com/security/CVE-2024-34490
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-34490.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2024-34490
Related
Published
2024-05-05T03:15:00Z
Modified
2024-10-15T14:14:11Z
Summary
[none]
Details

In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local attacker who can create files in advance with these names. This affects, for example, plot2d.

References

Affected packages

Ubuntu:Pro:16.04:LTS / maxima

Package

Name
maxima
Purl
pkg:deb/ubuntu/maxima?arch=src?distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.36.1-1
5.37.2-8

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / maxima

Package

Name
maxima
Purl
pkg:deb/ubuntu/maxima?arch=src?distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.40.0-1
5.40.0-3
5.41.0-1
5.41.0-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / maxima

Package

Name
maxima
Purl
pkg:deb/ubuntu/maxima?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.42.1-1build1
5.43.0-3
5.43.2-2
5.43.2-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / maxima

Package

Name
maxima
Purl
pkg:deb/ubuntu/maxima?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.44.0-3
5.45.1-2
5.45.1-4
5.45.1-5
5.45.1-6
5.45.1-7
5.45.1-8

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / maxima

Package

Name
maxima
Purl
pkg:deb/ubuntu/maxima?arch=src?distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.46.0-11build3
5.47.0-2
5.47.0-3
5.47.0-4

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / maxima

Package

Name
maxima
Purl
pkg:deb/ubuntu/maxima?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*

5.45.1-8
5.46.0-11
5.46.0-11build3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}