Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0219

Опубликовано: 23 янв. 2013
Источник: redhat
CVSS2: 3.7
EPSS Низкий

Описание

System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.

Дополнительная информация

Статус:

Low
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=884254sssd: TOCTOU race conditions by copying and removing directory trees

EPSS

Процентиль: 20%
0.00064
Низкий

3.7 Low

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.

nvd
больше 12 лет назад

System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.

debian
больше 12 лет назад

System Security Services Daemon (SSSD) before 1.9.4, when (1) creating ...

github
больше 3 лет назад

System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files.

oracle-oval
почти 12 лет назад

ELSA-2013-1319: sssd security and bug fix update (LOW)

EPSS

Процентиль: 20%
0.00064
Низкий

3.7 Low

CVSS2