3.3
CVSSv2

CVE-2011-1920

Published: 23/05/2011 Updated: 17/08/2017
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

The make include files in NetBSD prior to 1.6.2, as used in pmake 1.111 and other products, allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_depend##### temporary file, related to (1) bsd.lib.mk and (2) bsd.prog.mk.

Vulnerable Product Search on Vulmon Subscribe to Product

netbsd netbsd 1.3.1

netbsd netbsd 1.3.2

netbsd netbsd 1.2.1

netbsd netbsd 1.2

netbsd netbsd

netbsd netbsd 1.4.1

netbsd netbsd 1.5.3

netbsd netbsd 1.6

netbsd netbsd 1.3.3

netbsd netbsd 1.4

netbsd netbsd 1.5.1

netbsd netbsd 1.5.2

netbsd netbsd 1.3

netbsd netbsd 1.1

netbsd netbsd 1.0

netbsd netbsd 1.4.2

netbsd netbsd 1.5

netbsd netbsd 1.4.3

ihji pmake 1.111