Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-1893

Опубликовано: 14 июл. 2009
Источник: redhat
CVSS2: 5.6
EPSS Низкий

Описание

The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file, related to the "dhcpd -t" command.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=510024dhcp: insecure temporary file use in the dhcpd init script

EPSS

Процентиль: 45%
0.00602
Низкий

5.6 Medium

CVSS2

Связанные уязвимости

nvd
около 17 лет назад

The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file, related to the "dhcpd -t" command.

github
больше 4 лет назад

The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file, related to the "dhcpd -t" command.

EPSS

Процентиль: 45%
0.00602
Низкий

5.6 Medium

CVSS2