CVE-2009-4135
MEDIUM severity · CVSS 4.4 · CWE-59
4.4CVSS MEDIUM
Summary
The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.
Impact & exploitability
Attack vectorLocal
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)0%
AV:L/AC:M/Au:N/C:P/I:P/A:P
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=ae034822c535fa5 ↗
Additional information
- NVD record
- http://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=ae034822c535fa5Patch
- http://marc.info/?l=oss-security&m=126030454503441&w=2Patch
- http://secunia.com/advisories/37645
- http://secunia.com/advisories/37860
- http://secunia.com/advisories/62226
- http://www.mail-archive.com/bug-coreutils%40gnu.org/msg18779.html
- http://www.mail-archive.com/bug-coreutils%40gnu.org/msg18787.html
- http://www.openwall.com/lists/oss-security/2009/12/08/4Advisory