2.1
CVSSv2

CVE-2005-2231

Published: 12/07/2005 Updated: 05/09/2008
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

High Availability Linux Project Heartbeat 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

Vulnerable Product Search on Vulmon Subscribe to Product

high availability linux project heartbeat 1.2.3

Vendor Advisories

Eric Romang discovered that heartbeat created temporary files in an insecure manner This could allow a symlink attack to create or overwrite arbitrary files with root privileges as soon as heartbeat is started ...
The security update DSA 761-1 for heartbeat contained a bug which caused a regression  This problem is corrected with this advisory  For completeness below please find the original advisory text: Eric Romang discovered several insecure temporary file creations in heartbeat, the subsystem for High-Availability Linux For the old stable distrib ...