CVE-2009-1893
dhcp: insecure temporary file use in the dhcpd init script
Severity Score
6.9
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file, related to the "dhcpd -t" command.
La función configtest en la secuencia de comandos de inicio del DHCPD en Red Hat para DHCP 3.0.1 en Red Hat Enterprise Linux (RHEL) 3 permite a usuarios locales sobrescribir ficheros de su elección a través de un ataque de enlace simbólico sobre un fichero temporal no especificado, relativo al comando "dhcpd -t".
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2009-06-02 CVE Reserved
- 2009-07-17 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
- CWE-377: Insecure Temporary File
CAPEC
References (9)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/35831 | 2023-02-13 | |
http://www.redhat.com/support/errata/RHSA-2009-1154.html | 2023-02-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=510024 | 2009-07-14 | |
https://access.redhat.com/security/cve/CVE-2009-1893 | 2009-07-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | - |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc1 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | - |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc10 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | - |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc11 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | - |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc12 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | - |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc13 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | - |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc14 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | - |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc2 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | - |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc5 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | - |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc6 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | - |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc7 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | - |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc8 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | - |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc9 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | as |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc1 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | as |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc10 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | as |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc11 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | as |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc12 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | as |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc13 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | as |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc14 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | as |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc2 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | as |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc5 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | as |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc6 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | as |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc7 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | as |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc8 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | as |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc9 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | es |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc1 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | es |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc10 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | es |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc11 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | es |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc12 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | es |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc13 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | es |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc14 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | es |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc2 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | es |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc5 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | es |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc6 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | es |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc7 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | es |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc8 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | es |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc9 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | ws |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc1 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | ws |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc10 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | ws |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc11 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | ws |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc12 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | ws |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc13 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | ws |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc14 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | ws |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc2 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | ws |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc5 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | ws |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc6 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | ws |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc7 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | ws |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc8 |
Affected
|
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 3.0 Search vendor "Redhat" for product "Enterprise Linux" and version "3.0" | ws |
Affected
| in | Isc Search vendor "Isc" | Dhcp Search vendor "Isc" for product "Dhcp" | 3.0.1 Search vendor "Isc" for product "Dhcp" and version "3.0.1" | rc9 |
Affected
|