The GetHTMLRunDir function in the scan-build utility in...
Low severity
Unreviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
Apr 23, 2014
Published to the GitHub Advisory Database
May 14, 2022
Last updated
Feb 2, 2023
The GetHTMLRunDir function in the scan-build utility in Clang 3.5 and earlier allows local users to obtain sensitive information or overwrite arbitrary files via a symlink attack on temporary directories with predictable names.
References