uu_mktemp
Cross-platform Rust rewrite of the GNU coreutils
Activity
- Latest release
- 1w ago
- Total releases
- 40
- Cadence
- ~2 months
- Last 12 months
- 9
Reach
- Stars
- 24.0k
Details
- License
- MIT
- First release
- May 31, 2020
| Version | Released | |
|---|---|---|
0.11.0
minor
| ||
0.10.0
minor
| ||
0.9.0
unknown
| ||
0.8.0
unknown
| ||
0.7.0
unknown
| ||
0.6.0
unknown
| ||
0.5.0
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.4.0
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.3.0
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.2.2
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.2.0
unknown
yanked
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.1.0
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.30
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.29
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.28
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.27
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.26
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.25
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.24
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.23
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.22
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.21
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.20
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.19
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.18
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.17
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.16
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.15
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.14
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.13
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.12
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.9
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.8
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.7
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.6
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.5
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.4
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.3
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.2
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev | ||
0.0.1
unknown
1 CVE
CVE-2026-35342
GHSA-2w8r-9xj7-69j5
Jul 06, 2026
mktemp: empty TMPDIR creates temp files in CWD instead of /tmp
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
Low
None
None
The mktemp utility in uutils coreutils fails to properly handle an empty TMPDIR environment variable. Unlike GNU mktemp, which falls back to /tmp when TMPDIR is an empty string, the uutils implementation treats the empty string as a valid path. This causes temporary files to be created in the current working directory (CWD) instead of the intended secure temporary directory. If the CWD is more permissive or accessible to other users than /tmp, it may lead to unintended information disclosure or unauthorized access to temporary data. Zellic finding 3.11. Reported in the Zellic uutils coreutils Program Security Assessment (for Canonical, Jan 2026), audited commit Fixed in
0.6.0
References
Updated Jul 06, 2026 · Source: OSV.dev |