Red Hat · Kexec-Tools · CVE-2015-0267
**Name of the Vulnerable Software and Affected Versions**
kexec-tools versions prior to 2.0.7-19
**Description**
The issue allows local users to write to arbitrary files via a symlink attack on a temporary file. This is related to the Red Hat module-setup.sh script for kexec-tools in Red Hat Enterprise Linux.
**Recommendations**
For versions prior to 2.0.7-19, update to version 2.0.7-19 or later to resolve the issue. As a temporary workaround, consider restricting access to the module-setup.sh script to minimize the risk of exploitation.