Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0267

Опубликовано: 10 фев. 2015
Источник: redhat
CVSS2: 3.6
EPSS Низкий

Описание

The Red Hat module-setup.sh script for kexec-tools, as distributed in the kexec-tools before 2.0.7-19 packages in Red Hat Enterprise Linux, allows local users to write to arbitrary files via a symlink attack on a temporary file.

It was found that the module-setup.sh script provided by kexec-tools created temporary files in an insecure way. A malicious, local user could use this flaw to conduct a symbolic link attack, allowing them to overwrite the contents of arbitrary files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kexec-toolsNot affected
Red Hat Enterprise Linux 6kexec-toolsNot affected
Red Hat Enterprise Linux 7kexec-toolsFixedRHSA-2015:098612.05.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=1191575kexec-tools: insecure use of /tmp/*$$* filenames

EPSS

Процентиль: 15%
0.00049
Низкий

3.6 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The Red Hat module-setup.sh script for kexec-tools, as distributed in the kexec-tools before 2.0.7-19 packages in Red Hat Enterprise Linux, allows local users to write to arbitrary files via a symlink attack on a temporary file.

nvd
больше 10 лет назад

The Red Hat module-setup.sh script for kexec-tools, as distributed in the kexec-tools before 2.0.7-19 packages in Red Hat Enterprise Linux, allows local users to write to arbitrary files via a symlink attack on a temporary file.

debian
больше 10 лет назад

The Red Hat module-setup.sh script for kexec-tools, as distributed in ...

github
больше 3 лет назад

The Red Hat module-setup.sh script for kexec-tools, as distributed in the kexec-tools before 2.0.7-19 packages in Red Hat Enterprise Linux, allows local users to write to arbitrary files via a symlink attack on a temporary file.

oracle-oval
больше 10 лет назад

ELSA-2015-0986: kexec-tools security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 15%
0.00049
Низкий

3.6 Low

CVSS2