PT-2019-7008 · Slackware+1 · Slackware+1
Murray Mcallister
·
Published
2019-11-21
·
Updated
2019-12-03
·
CVE-2013-7171
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Slackware versions 14.0 through 14.1
Slackware LLVM versions 3.0-i486-2 through 3.3-i486-2
Description
The issue allows remote attackers to execute arbitrary code with root privileges due to world-writable permissions on the /tmp directory.
Recommendations
For Slackware versions 14.0 through 14.1, change the permissions of the /tmp directory to prevent world-writable access.
For Slackware LLVM versions 3.0-i486-2 through 3.3-i486-2, modify the permissions of the /tmp directory to restrict unauthorized access.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Llvm
Slackware