CVE-2019-17365

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/10/2019
Last modified:
15/01/2025

Description

Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nixos:nix:*:*:*:*:*:*:*:* 2.3 (including)