4.4
CVSSv2

CVE-2009-1297

Published: 23/10/2009 Updated: 30/10/2018
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 up to and including 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file that has a predictable name.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 10.3

opensuse opensuse 11.1

novell suse linux 11

novell suse linux 10

Vendor Advisories

Debian Bug report logs - #547011 Insecure temporary file name in iscsi_discovery Package: open-iscsi; Maintainer for open-iscsi is Debian iSCSI Maintainers <open-iscsi@packagesdebianorg>; Source for open-iscsi is src:open-iscsi (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 16 Sep ...
iscsi_discovery in open-iscsi could be made to overwrite files as the administrator ...