Incorrect Authorization in SimGear
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.6epss 0.4%
exploitation probability
0.4%top 73% of all CVEs
observed exploitation
nono source reports it
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected products
FlightGear · SimGearReferences
https://gitlab.com/flightgear/flightgear/-/commit/ad37afce28083fad7f79467b3ffdead753584358https://gitlab.com/flightgear/flightgear/-/issues/3025https://gitlab.com/flightgear/simgear/-/commit/5bb023647114267141a7610e8f1ca7d6f4f5a5a8https://lists.debian.org/debian-lts-announce/2025/01/msg00028.htmlhttps://lists.debian.org/debian-lts-announce/2025/01/msg00029.html