An issue was found in the CPython `tempfile.TemporaryDirectory` class
affecting versions 3.12.2, 3.11.8, 3.10.13, 3.9.18, and 3.8.18 and prior.

The tempfile.TemporaryDirectory class would dereference symlinks during
cleanup of permissions-related errors. This means users which can run
privileged programs are potentially able to modify permissions of files
referenced by symlinks in some circumstances.

*References*
* CVE: https://www.cve.org/CVERecord?id=CVE-2023-6597
* Patch: https://github.com/python/cpython/pull/99930
* Issue: https://github.com/python/cpython/issues/91133
_______________________________________________
Security-announce mailing list -- security-annou...@python.org
To unsubscribe send an email to security-announce-le...@python.org
https://mail.python.org/mailman3/lists/security-announce.python.org/
Member address: arch...@mail-archive.com

Reply via email to