Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-1088

Опубликовано: 15 фев. 2012
Источник: redhat
CVSS2: 1.9

Описание

iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script.

Отчет

These issues only affect a script used during package build and do not affect binary iproute packages shipped with Red Hat Enterprise Linux. Therefore, they are not planned to be addressed in iproute packages in Red Hat Enterprise Linux 5 and 6, they are only planned to be addressed in the future Red Hat Enterprise Linux versions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4iprouteWill not fix
Red Hat Enterprise Linux 5iprouteWill not fix
Red Hat Enterprise Linux 6iprouteWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=797878iproute: multiple insecure temporary file use issues

1.9 Low

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script.

nvd
больше 12 лет назад

iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script.

debian
больше 12 лет назад

iproute2 before 3.3.0 allows local users to overwrite arbitrary files ...

github
около 4 лет назад

iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script.

1.9 Low

CVSS2