CVE-2024-34490

NameCVE-2024-34490
DescriptionIn Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local attacker who can create files in advance with these names. This affects, for example, plot2d.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
maxima (PTS)buster5.42.1-1vulnerable
bullseye5.44.0-3vulnerable
sid, trixie, bookworm5.46.0-11vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
maximasource(unstable)(unfixed)

Notes

[bookworm] - maxima <no-dsa> (Minor issue)
[bullseye] - maxima <no-dsa> (Minor issue)
[buster] - maxima <postponed> (Minor issue)
https://sourceforge.net/p/maxima/bugs/3755/

Search for package or bug name: Reporting problems