PT-2024-11774 · Fdupes+1 · Fdupes+1

·

CVE-2022-48682

·

Published

2024-04-26

·

Updated

2024-10-27

CVSS v3.1

6.0

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions FDUPES versions prior to 2.2.0
Description A TOCTOU race condition in the deletefiles function allows for arbitrary file deletion via a symlink.
Recommendations For FDUPES versions prior to 2.2.0, update to version 2.2.0 or later to resolve the issue.

Exploit

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-48682
OESA-2024-1532
OESA-2024-1615
OESA-2024-1616

Affected Products

Debian
Fdupes