Synced 30 Sept 2026 23:45 UTC Account
← All products

CVE-2009-4135

MEDIUM severity · CVSS 4.4 · CWE-59
4.4CVSS MEDIUM

Summary

The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.

Impact & exploitability

Attack vectorLocal
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)0%

AV:L/AC:M/Au:N/C:P/I:P/A:P

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: http://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=ae034822c535fa5 ↗