{"id":"GHSA-xwg2-qc6c-7c3q","summary":"Fabric vulnerable to symlink attack on tmp files","details":"Fabric before 1.1.0 allows local users to overwrite arbitrary files via a symlink attack on (1) a `/tmp/fab.*.tar` file or (2) certain other files in the top level of `/tmp/`.","aliases":["CVE-2011-2185","PYSEC-2026-808"],"modified":"2026-07-07T11:56:27.400326336Z","published":"2022-05-17T05:40:10Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-01-19T18:16:49Z","nvd_published_at":"2011-07-27T02:55:00Z","cwe_ids":["CWE-59"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-2185"},{"type":"WEB","url":"https://github.com/fabric/fabric/commit/3445b5653cd297039443110548fb3cab2e8e25af"},{"type":"WEB","url":"https://github.com/fabric/fabric/commit/d7470d2db919ffcee80c245cf87e6d8d4ba6909c"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=710462"},{"type":"PACKAGE","url":"https://github.com/fabric/fabric"},{"type":"WEB","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=629003"},{"type":"WEB","url":"http://code.fabfile.org/projects/fabric/files/Fabric-1.1.0.tar.gz"},{"type":"WEB","url":"http://lists.fedoraproject.org/pipermail/package-announce/2011-July/062534.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/06/03/5"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/06/06/12"}],"affected":[{"package":{"name":"fabric","ecosystem":"PyPI","purl":"pkg:pypi/fabric"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.0"}]}],"versions":["0.0.1","0.0.2","0.0.3","0.0.4","0.0.5","0.0.6","0.0.7","0.0.8","0.0.9","0.1.0","0.1.1","0.9.0","0.9.1","0.9.2","0.9.3","0.9.4","0.9.5","0.9.6","0.9.7","1.0.0","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xwg2-qc6c-7c3q/GHSA-xwg2-qc6c-7c3q.json"}}],"schema_version":"1.9.0"}