CVE-2023-34204

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
30/05/2023
Last modified:
10/01/2025

Description

imapsync through 2.229 uses predictable paths under /tmp and /var/tmp in its default mode of operation. Both of these are typically world-writable, and thus (for example) an attacker can modify imapsync's cache and overwrite files belonging to the user who runs it.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:imapsync_project:imapsync:*:*:*:*:*:*:*:* 2.229 (including)