PT-2010-4297 · Red Hat · Spice+1

Petr Matousek

·

Published

2010-08-25

·

Updated

2024-03-12

·

CVE-2010-2794

CVSS v2.0

3.3

Low

VectorAV:L/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions SPICE (aka spice-xpi) plug-in version 2.2
Description The issue allows local users to overwrite arbitrary files via a symlink attack on an unspecified log file.
Recommendations For SPICE (aka spice-xpi) plug-in version 2.2, consider removing or disabling the plug-in until a patch is available to prevent potential file overwrites.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2794
RHSA-2010:0651
RHSA-2010_0651
ROSA-SA-2024-2370

Affected Products

Red Hat
Spice