VYPR
Unrated severityNVD Advisory· Published Nov 12, 2019· Updated Aug 7, 2024

CVE-2010-3440

CVE-2010-3440

Description

babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary files, allowing a local attacker to overwrite arbitrary files.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Babiloo 2.0.9 through 2.0.10 creates predictable temporary file names, enabling a local attacker to overwrite arbitrary files.

Vulnerability

Babiloo versions 2.0.9 to 2.0.10 (before 2.0.11) create temporary files with predictable names when downloading and unpacking dictionary files. This vulnerability resides in the file handling code used during dictionary extraction, and no special configuration is required beyond using the affected version with the dictionary download feature.

Exploitation

A local attacker with knowledge of the predictable temporary file naming scheme can time an attack to overwrite an arbitrary file on the system. The attacker does not require any authentication beyond local access, and the exploitation window is during the extraction process triggered by a user downloading a dictionary file.

Impact

Successful exploitation allows the local attacker to overwrite arbitrary files, potentially leading to denial of service, privilege escalation, or data corruption depending on the target file. The compromise is limited to file overwriting; code execution is not directly described in the references.[1]

Mitigation

The issue is fixed in Babiloo version 2.0.11. Users should upgrade to this version or later. If an upgrade is not immediately possible, avoid using the dictionary download feature or apply restrictive file permissions to mitigate exploitation.[2] The vulnerability does not appear on the CISA KEV list.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.