IM
IronMonkey Threat Research

CVE-2025-7039 LOW

Published: 2025-09-03 | Last Modified: 2026-06-02 | Status: Deferred

Description

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.

CVSS Metrics

Base Score: 3.7 (LOW)

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactLOW
Availability ImpactNONE

Source: [email protected]

Type: Secondary

Exploitability Score: 2.2

Impact Score: 1.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-22
Notification
Message here