replay-sorcery-kms in Replay Sorcery 0.6.0 allows a local attacker to gain root privileges via a symlink attack on /tmp/replay-sorcery or /tmp/replay-sorcery/device.sock.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://github.com/matanui159/ReplaySorcery/releases | third party advisory release notes |
http://www.openwall.com/lists/oss-security/2021/07/27/1 | third party advisory mailing list |