CVE-2010-3440
Description
babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary files, allowing a local attacker to overwrite arbitrary files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Babiloo 2.0.9 through 2.0.10 creates predictable temporary file names, enabling a local attacker to overwrite arbitrary files.
Vulnerability
Babiloo versions 2.0.9 to 2.0.10 (before 2.0.11) create temporary files with predictable names when downloading and unpacking dictionary files. This vulnerability resides in the file handling code used during dictionary extraction, and no special configuration is required beyond using the affected version with the dictionary download feature.
Exploitation
A local attacker with knowledge of the predictable temporary file naming scheme can time an attack to overwrite an arbitrary file on the system. The attacker does not require any authentication beyond local access, and the exploitation window is during the extraction process triggered by a user downloading a dictionary file.
Impact
Successful exploitation allows the local attacker to overwrite arbitrary files, potentially leading to denial of service, privilege escalation, or data corruption depending on the target file. The compromise is limited to file overwriting; code execution is not directly described in the references.[1]
Mitigation
The issue is fixed in Babiloo version 2.0.11. Users should upgrade to this version or later. If an upgrade is not immediately possible, avoid using the dictionary download feature or apply restrictive file permissions to mitigate exploitation.[2] The vulnerability does not appear on the CISA KEV list.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- babiloo/babiloov5Range: 2.0.9 before 2.0.11
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- access.redhat.com/security/cve/cve-2010-3440mitrex_refsource_MISC
- bugs.debian.org/cgi-bin/bugreport.cgimitrex_refsource_MISC
- security-tracker.debian.org/tracker/CVE-2010-3440mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.