4.4
CVSSv2

CVE-2009-4135

Published: 11/12/2009 Updated: 13/02/2023
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 up to and including 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 10.04

gnu coreutils 6.6

gnu coreutils 6.10

gnu coreutils 5.96

gnu coreutils 5.91

gnu coreutils 6.4

gnu coreutils 6.12

gnu coreutils 5.2.1

gnu coreutils 7.6

gnu coreutils 6.8

gnu coreutils 6.7

gnu coreutils 8.1

gnu coreutils 7.1

gnu coreutils 6.11

gnu coreutils 7.3

gnu coreutils 7.4

gnu coreutils 5.97

gnu coreutils 5.94

gnu coreutils 5.93

gnu coreutils 6.5

gnu coreutils 6.9

gnu coreutils 6.2

gnu coreutils 5.95

gnu coreutils 7.2

gnu coreutils 7.5

gnu coreutils 5.92

gnu coreutils 6.3

fedoraproject fedora 11

fedoraproject fedora 12

Vendor Advisories

date and touch could be made to crash or run programs if they handled specially crafted input ...