CVE-2023-6597
Vulnerability Summary
Timeline
Description
An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior. The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are potentially able to modify permissions of files referenced by symlinks in some circumstances.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
EPSS Trends
Current EPSS score: 0.31%• Percentile: 24%
Affected Systems
- alpine•python3
< 3.10.14-r0 | < 3.10.14-r0
- chainguard•aws-cli-v2
< 2.15.35-r0
- chainguard•python-3.10
< 3.10.14-r0
- chainguard•python-3.11
< 3.11.8-r0
- chainguard•python-3.12
< 3.12.2-r0
- chainguard•python-3.12-base
< 3.12.2-r0
- chainguard•python-3.12-base-dev
< 3.12.2-r0
- chainguard•python-3.12-dev
< 3.12.2-r0
- chainguard•python-3.12-doc
< 3.12.2-r0
- chainguard•python-3.12-privileged-netbindservice
< 3.12.2-r0
- chainguard•python-3.12-tk
< 3.12.2-r0
- chainguard•python-3.9
< 3.9.19-r0
- wolfi•aws-cli-v2
< 2.15.35-r0
- wolfi•python-3.10
< 3.10.14-r0
- wolfi•python-3.11
< 3.11.8-r0
- wolfi•python-3.12
< 3.12.2-r0
- wolfi•python-3.12-base
< 3.12.2-r0
- wolfi•python-3.12-base-dev
< 3.12.2-r0
- wolfi•python-3.12-dev
< 3.12.2-r0
- wolfi•python-3.12-doc
< 3.12.2-r0
- wolfi•python-3.12-privileged-netbindservice
< 3.12.2-r0
- wolfi•python-3.12-tk
< 3.12.2-r0
- debian•pypy3
< 7.3.5+dfsg-2+deb11u3 | < 7.3.11+dfsg-2+deb12u2 | < 7.3.13+dfsg-1 | < 7.3.13+dfsg-1
- debian•python3.11
< 3.11.2-6+deb12u2
- debian•python3.9
< 3.9.2-1+deb11u2
- ubuntu•python3.10
< 3.10.12-1~22.04.4
- ubuntu•python3.11
< 3.11.0~rc1-1~22.04.1~esm1
- ubuntu•python3.4
all
- ubuntu•python3.5
< 3.5.2-2ubuntu0~16.04.13+esm13
- ubuntu•python3.7
< 3.7.5-2ubuntu1~18.04.2+esm3
- ubuntu•python3.8
< 3.8.0-3ubuntu1~18.04.2+esm2 | < 3.8.10-0ubuntu1~20.04.10
- ubuntu•python3.9
< 3.9.5-3ubuntu0~20.04.1+esm2
- python software foundation•cpython
< 3.8.19 | ≥ 3.9.0, < 3.9.19 | ≥ 3.10.0, < 3.10.14 | ≥ 3.11.0, < 3.11.8 | ≥ 3.12.0, < 3.12.1 | ≥ 3.13.0a1, < 3.13.0a3
- redhat•platform-python
< 0:3.6.8-24.el8_2.3 | < 0:3.6.8-24.el8_2.3 | < 0:3.6.8-39.el8_4.5 | < 0:3.6.8-39.el8_4.5
- redhat•platform-python-debug
< 0:3.6.8-24.el8_2.3 | < 0:3.6.8-39.el8_4.5
- redhat•platform-python-devel
< 0:3.6.8-24.el8_2.3 | < 0:3.6.8-39.el8_4.5
- redhat•python-unversioned-command
< 0:3.9.16-1.el9_2.5 | < 0:3.9.10-4.el9_0.4
- redhat•python3
< 0:3.6.8-24.el8_2.3 | < 0:3.6.8-39.el8_4.5 | < 0:3.9.16-1.el9_2.5 | < 0:3.9.16-1.el9_2.5 | < 0:3.9.10-4.el9_0.4
- redhat•python3-debug
< 0:3.9.16-1.el9_2.5
- redhat•python3-debuginfo
< 0:3.6.8-24.el8_2.3 | < 0:3.6.8-24.el8_2.3 | < 0:3.6.8-39.el8_4.5 | < 0:3.6.8-39.el8_4.5
- redhat•python3-debugsource
< 0:3.6.8-24.el8_2.3 | < 0:3.6.8-24.el8_2.3 | < 0:3.6.8-39.el8_4.5 | < 0:3.6.8-39.el8_4.5
- redhat•python3-devel
< 0:3.9.16-1.el9_2.5 | < 0:3.9.10-4.el9_0.4
- redhat•python3-idle
< 0:3.6.8-24.el8_2.3 | < 0:3.6.8-39.el8_4.5 | < 0:3.9.16-1.el9_2.5
- redhat•python3-libs
< 0:3.6.8-24.el8_2.3 | < 0:3.6.8-39.el8_4.5 | < 0:3.9.16-1.el9_2.5 | < 0:3.9.10-4.el9_0.4
- redhat•python3-test
< 0:3.6.8-24.el8_2.3 | < 0:3.6.8-24.el8_2.3 | < 0:3.6.8-39.el8_4.5 | < 0:3.6.8-39.el8_4.5 | < 0:3.9.16-1.el9_2.5
- redhat•python3-tkinter
< 0:3.6.8-24.el8_2.3 | < 0:3.6.8-39.el8_4.5 | < 0:3.9.16-1.el9_2.5 | < 0:3.9.16-1.el9_2.5 | < 0:3.9.10-4.el9_0.4
- redhat•python3.11
< 0:3.11.7-1.el9_4.1 | < 0:3.11.7-1.el9_4.1 | < 0:3.11.2-2.el8_8.3 | < 0:3.11.2-2.el8_8.3 | < 0:3.11.2-2.el9_2.4 | < 0:3.11.2-2.el9_2.4
- redhat•python3.11-debug
< 0:3.11.7-1.el9_4.1 | < 0:3.11.2-2.el8_8.3 | < 0:3.11.2-2.el9_2.4
- redhat•python3.11-debuginfo
< 0:3.11.7-1.el9_4.1 | < 0:3.11.7-1.el9_4.1 | < 0:3.11.2-2.el8_8.3 | < 0:3.11.2-2.el8_8.3 | < 0:3.11.2-2.el9_2.4 | < 0:3.11.2-2.el9_2.4
- redhat•python3.11-debugsource
< 0:3.11.7-1.el9_4.1 | < 0:3.11.7-1.el9_4.1 | < 0:3.11.2-2.el8_8.3 | < 0:3.11.2-2.el8_8.3 | < 0:3.11.2-2.el9_2.4 | < 0:3.11.2-2.el9_2.4
Showing first 50 affected entries in server-rendered view.
References (42)
- https://github.com/python/cpython/commit/81c16cd94ec38d61aa478b9a452436dc3b1b524d
- https://github.com/python/cpython/commit/6ceb8aeda504b079fef7a57b8d81472f15cdd9a5
- https://github.com/python/cpython/commit/5585334d772b253a01a6730e8202ffb1607c3d25
- https://github.com/python/cpython/commit/8eaeefe49d179ca4908d052745e3bb8b6f238f82
- https://github.com/python/cpython/commit/d54e22a669ae6e987199bb5d2c69bb5a46b0083b
- https://github.com/python/cpython/commit/02a9259c717738dfe6b463c44d7e17f2b6d2cb3a
- https://github.com/python/cpython/issues/91133
- https://mail.python.org/archives/list/security-announce@python.org/thread/Q5C6ATFC67K53XFV4KE45325S7NS62LD/
- https://lists.debian.org/debian-lts-announce/2024/03/msg00025.html
- http://www.openwall.com/lists/oss-security/2024/03/20/5
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3IGRX54M7RNCQOXVQO5KQKTGWCOABIM/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5VHWS52HGD743C47UMCSAK2A773M2YE/
- https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html
- https://lists.debian.org/debian-lts-announce/2024/11/msg00005.html
- https://security.alpinelinux.org/vuln/CVE-2023-6597
- https://access.redhat.com/errata/RHSA-2024:4077
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2276518
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4077.json
- https://access.redhat.com/security/cve/CVE-2023-6597
- https://www.cve.org/CVERecord?id=CVE-2023-6597
- https://nvd.nist.gov/vuln/detail/CVE-2023-6597
- https://access.redhat.com/errata/RHSA-2024:4166
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4166.json
- https://access.redhat.com/errata/RHSA-2024:4370
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4370.json
- https://access.redhat.com/errata/RHSA-2024:4456
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4456.json
- https://access.redhat.com/errata/RHSA-2024:4896
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4896.json
- https://access.redhat.com/errata/RHSA-2024:5535
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_5535.json
- https://access.redhat.com/errata/RHSA-2024:5689
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_5689.json
- https://security-tracker.debian.org/tracker/CVE-2023-6597
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/6xxx/CVE-2023-6597.json
- https://github.com/python/cpython
- https://ubuntu.com/security/CVE-2023-6597
- https://seclists.org/oss-sec/2024/q1/240
- https://discuss.python.org/t/python-3-10-14-3-9-19-and-3-8-19-is-now-available/48993
- https://ubuntu.com/security/notices/USN-6891-1
- https://github.com/advisories/GHSA-797f-63wg-8chv