CVE-2017-8921
Description
In FlightGear before 2017.2.1, the FGCommand interface allows overwriting any file the user has write access to, but not with arbitrary data: only with the contents of a FlightGear flightplan (XML). A resource such as a malicious third-party aircraft could exploit this to damage files belonging to the user. Both this issue and CVE-2016-9956 are directory traversal vulnerabilities in Autopilot/route_mgr.cxx - this one exists because of an incomplete fix for CVE-2016-9956.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | fixed | 1:2016.4.4+dfsg-3 |
| debian | bullseye | fixed | 1:2016.4.4+dfsg-3 |
| debian | forky | fixed | 1:2016.4.4+dfsg-3 |
| debian | sid | fixed | 1:2016.4.4+dfsg-3 |
| debian | trixie | fixed | 1:2016.4.4+dfsg-3 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| flightgear | flightgear | {"endIncluding":"2017.2"} | |
References
CWEs
CWE-22
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.