CVE-2024-34490

NameCVE-2024-34490
DescriptionIn Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local attacker who can create files in advance with these names. This affects, for example, plot2d.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1071630

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
maxima (PTS)bullseye5.44.0-3vulnerable
bookworm5.46.0-11vulnerable
sid, trixie5.47.0-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
maximasource(unstable)5.47.0-1unimportant1071630

Notes

https://sourceforge.net/p/maxima/bugs/3755/
https://sourceforge.net/p/maxima/code/ci/51704ccb090f6f971b641e4e0b7c1c22c4828bf7/
Neutralised by kernel hardening

Search for package or bug name: Reporting problems