Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2025-0913

Description

os.OpenFile(path, os.O_CREATE|O_EXCL) behaved differently on Unix and Windows systems when the target path was a dangling symlink. On Unix systems, OpenFile with O_CREATE and O_EXCL flags never follows symlinks. On Windows, when the target path was a symlink to a nonexistent location, OpenFile would create a file in that location. OpenFile now always returns an error when the O_CREATE and O_EXCL flags are both set and the target path is a symlink.

POC

Reference

No PoCs from references.

Github

- https://github.com/8-cm/kube-dump

- https://github.com/ARPSyndicate/cve-scores

- https://github.com/ReneDiff/TrivyExternImageTest

- https://github.com/TAMULib/metadb-docker

- https://github.com/fkie-cad/nvd-json-data-feeds

- https://github.com/straubt1/tf-provider-scanning