Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Harald Hoyer

Pesquisador deRed Hat
#52672de 53,640
3.6CVSS total
Vulnerabilidades · 1
PT-2015-4553
3.6
2015-02-12
Red Hat · Kexec-Tools · CVE-2015-0267
**Name of the Vulnerable Software and Affected Versions** kexec-tools versions prior to 2.0.7-19 **Description** The issue allows local users to write to arbitrary files via a symlink attack on a temporary file. This is related to the Red Hat module-setup.sh script for kexec-tools in Red Hat Enterprise Linux. **Recommendations** For versions prior to 2.0.7-19, update to version 2.0.7-19 or later to resolve the issue. As a temporary workaround, consider restricting access to the module-setup.sh script to minimize the risk of exploitation.