PT-2008-1034 · Unknown · Policyd-Weight
Chris Howells
·
Published
2008-03-31
·
Updated
2017-08-08
·
CVE-2008-1570
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
policyd-weight version 0.1.14 beta-16
Description
The issue is related to a race condition in the
create lockpath function, allowing local users to modify or delete arbitrary files. This occurs by creating the LOCKPATH directory and then modifying it after the symbolic link check. The problem is due to an incomplete fix for a previous issue. Additionally, there are multiple vulnerabilities in the policyd-weight package that can lead to breaches of confidentiality, integrity, and availability of protected information, which can be exploited by a local attacker.Recommendations
For policyd-weight version 0.1.14 beta-16, consider disabling the
create lockpath function as a temporary workaround until a patch is available. Restrict access to the LOCKPATH directory to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Link Following
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Policyd-Weight