Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-2029

Опубликовано: 30 апр. 2013
Источник: redhat
CVSS2: 4.6
EPSS Низкий

Описание

nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arbitrary files via a symlink attack on a temporary nagioscfg file with a predictable name in /tmp/.

Отчет

The Red Hat Security Response Team has rated this issue as having moderate security impact. This issue is not currently planned to be addressed in OpenStack 2.1 (Folsom). For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 4nagiosAffected
OpenStack 3 for RHEL 6nagiosFixedRHSA-2013:152618.11.2013

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=958015core: Insecure temporary file usage in nagios.upgrade_to_v3.sh

EPSS

Процентиль: 28%
0.00354
Низкий

4.6 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arbitrary files via a symlink attack on a temporary nagioscfg file with a predictable name in /tmp/.

nvd
больше 12 лет назад

nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arbitrary files via a symlink attack on a temporary nagioscfg file with a predictable name in /tmp/.

debian
больше 12 лет назад

nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others ...

github
около 4 лет назад

nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arbitrary files via a symlink attack on a temporary nagioscfg file with a predictable name in /tmp/.

EPSS

Процентиль: 28%
0.00354
Низкий

4.6 Medium

CVSS2