1 results (0.017 seconds)

CVSS: 6.9EPSS: 0%CPEs: 43EXPL: 0

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9. Red Hat Cluster Project v2.x permite a usuarios locales modificar o sobrescribir ficheros de su elección mediante ataques de enlaces simbólicos a ficheros en /tmp, implicando componentes no especificados en Resource Group Manager (también conocido como rgmanager) versiones anteriores a v2.03.09-1, en gfs2-utils versiones anteriore a v2.03.09-1, y en CMAN - The Cluster Manager versiones anteriores a v2.03.09-1 para Fedora 9. • http://osvdb.org/50299 http://osvdb.org/50300 http://osvdb.org/50301 http://rhn.redhat.com/errata/RHSA-2009-1337.html http://secunia.com/advisories/32602 http://secunia.com/advisories/32616 http://secunia.com/advisories/36530 http://secunia.com/advisories/36555 http://secunia.com/advisories/43367 http://secunia.com/advisories/43372 http://www.redhat.com/archives/fedora-package-announce/2008-November/msg00163.html http://www.redhat.com/archives/fedora-package-announce/ • CWE-59: Improper Link Resolution Before File Access ('Link Following') CWE-377: Insecure Temporary File •