Improper Link Resolution in TUBITAK BILGEM Software Affects Pardus About
CVE-2026-5161

8.8HIGH

What is CVE-2026-5161?

The vulnerability presents an improper link resolution before file access within the TUBITAK BILGEM Software Technologies Research Institute's Pardus About. This inadequate handling of symbolic links can be exploited to perform a symlink attack, potentially allowing unauthorized file access and manipulation. The issue affects versions of Pardus About released before v1.2.1, highlighting critical concerns for users and administrators managing the software.

Affected Version(s)

Pardus About 0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Çağrı ESER
.