dandavison delta before 0.8.3 on Windows resolves an executable's pathname as a relative path from the current directory.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://github.com/dandavison/delta/commit/f01846bd443aaf92fdd5ac20f461beac3f6ee3fd | third party advisory patch |
https://vuln.ryotak.me/advisories/54 | third party advisory |
https://github.com/dandavison/delta/releases/tag/0.8.3 | third party advisory release notes |