The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file.
| Software | From | Fixed in |
|---|---|---|
github.com/github/hub
|
- | 1.12.1 |
| github / hub | - | 1.12.0.x |