PT-2013-1179 · Red Hat+1 · Red Hat+2
Florian Weimer
·
Publicado
2013-02-20
·
Atualizado
2024-06-15
·
CVE-2013-0219
CVSS v2.0
3.7
Baixa
| Vetor | AV:L/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SSSD versions prior to 1.9.4
Red Hat Enterprise Linux (affected versions not specified)
Description
The issue allows local users to create, modify, or delete arbitrary files via a symlink attack on another user's files, potentially leading to disruption of confidentiality, integrity, and availability of protected information. This can be exploited locally.
Recommendations
For versions prior to 1.9.4, update to version 1.9.4 or later to resolve the issue.
As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Red Hat
Sssd