CVE-2013-4116
Publication date 22 April 2014
Last updated 24 July 2024
Ubuntu priority
Description
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| npm | 18.04 LTS bionic |
Not affected
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
|