World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this directory.
{ "binaries": [ { "binary_name": "tmate-ssh-server", "binary_version": "2.3.0-49-g97d20249-1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-44512.json"
{ "binaries": [ { "binary_name": "tmate-ssh-server", "binary_version": "2.3.0-68-gd7334ee4-1build1" } ] }
{ "binaries": [ { "binary_name": "tmate-ssh-server", "binary_version": "2.3.0-68-gd7334ee4-2" } ] }