CVE-2014-2893: Llvm Clang

Low severity, CVSS 1.9. EPSS: 0.4% chance of exploitation in the next 30 days.

The GetHTMLRunDir function in the scan-build utility in Clang 3.5 and earlier allows local users to obtain sensitive information or overwrite arbitrary files via a symlink attack on temporary directories with predictable names.

Affected products

  • Llvm Clang: up to and including 3.5
  • Opensuse Opensuse: version 13.1 only

Published 2014-04-23. Last modified 2026-06-17.