Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Leif Nixon

#52958of 53,633
3.3Total CVSS
Vulnerabilities · 1
PT-2010-5336
3.3
2010-11-22
Libosdp · Libosdp · CVE-2010-4173
**Name of the Vulnerable Software and Affected Versions** libsdp versions 1.1.104 and earlier **Description** The default configuration of libsdp.conf in libsdp creates log files in /tmp, which allows local users to overwrite arbitrary files via a (1) symlink or (2) hard link attack on the libsdp.log temporary file. **Recommendations** For versions 1.1.104 and earlier, consider changing the default log file location from /tmp to a more secure directory to prevent local users from overwriting arbitrary files. As a temporary workaround, restrict access to the /tmp directory to minimize the risk of exploitation.