CVE-2025-0781 Information
Jan 30, 2025
cve
Description
An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating-system level.
Reference
https://gitlab.com/flightgear/flightgear/-/commit/ad37afce28083fad7f79467b3ffdead753584358 https://gitlab.com/flightgear/flightgear/-/issues/3025 https://gitlab.com/flightgear/simgear/-/commit/5bb023647114267141a7610e8f1ca7d6f4f5a5a8 https://lists.debian.org/debian-lts-announce/2025/01/msg00028.html https://lists.debian.org/debian-lts-announce/2025/01/msg00029.html
Share on: