6.9
CVSSv2

CVE-2008-1570

Published: 31/03/2008 Updated: 08/08/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating the LOCKPATH directory, then modifying it after the symbolic link check occurs. NOTE: this is due to an incomplete fix for CVE-2008-1569.

Vulnerable Product Search on Vulmon Subscribe to Product

policyd-weight policyd-weight 0.1.14_beta-14

Vendor Advisories

Debian Bug report logs - #736958 ruby-passenger: CVE-2014-1831: insecure use of /tmp Package: src:ruby-passenger; Maintainer for src:ruby-passenger is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Jakub Wilk <jwilk@debianorg> Date: Tue, 28 Jan 2014 19:21:02 UTC Se ...