Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-12779

Опубликовано: 07 июн. 2019
Источник: debian
EPSS Низкий

Описание

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libqbfixed1.0.4-1package
libqbend-of-lifejessiepackage

Примечания

  • https://github.com/ClusterLabs/libqb/issues/338

  • https://github.com/ClusterLabs/libqb/commit/6a4067c1d1764d93d255eccecfd8bf9f43cb0b4d

  • Regression fix: https://github.com/ClusterLabs/libqb/pull/349

  • Neutralised by kernel hardening

EPSS

Процентиль: 48%
0.00655
Низкий

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 7 лет назад

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

CVSS3: 6.5
redhat
больше 7 лет назад

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

CVSS3: 7.1
nvd
около 7 лет назад

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

suse-cvrf
около 7 лет назад

Security update for libqb

suse-cvrf
около 7 лет назад

Security update for libqb

EPSS

Процентиль: 48%
0.00655
Низкий