This issue affects pardus-image-writer: before 1.0.4.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 04 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Aug 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Important Client Functionality. This issue affects pardus-image-writer: before 1.0.4. | |
| Title | Arbitrary Block Device Write via Missing Validation in TÜBİTAK BİLGEM's pardus-image-writer | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TR-CERT
Published:
Updated: 2026-08-04T15:37:47.429Z
Reserved: 2026-08-04T12:12:44.857Z
Link: CVE-2026-18806
Updated: 2026-08-04T15:37:43.214Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-04T20:00:05Z
-
CWE-73
External Control of File Name or Path