Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9595

Опубликовано: 21 дек. 2016
Источник: redhat
CVSS3: 7.3
CVSS2: 6.9
EPSS Низкий

Описание

A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.

A flaw was found in katello-debug where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=1406729katello-debug: Possible symlink attacks due to use of predictable file names

EPSS

Процентиль: 13%
0.00042
Низкий

7.3 High

CVSS3

6.9 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.3
nvd
больше 7 лет назад

A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.

CVSS3: 5.5
github
больше 3 лет назад

A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.

EPSS

Процентиль: 13%
0.00042
Низкий

7.3 High

CVSS3

6.9 Medium

CVSS2