5.6
CVSSv2

CVE-2012-3440

Published: 08/08/2012 Updated: 13/02/2023
CVSS v2 Base Score: 5.6 | Impact Score: 9.2 | Exploitability Score: 1.9
VMScore: 498
Vector: AV:L/AC:H/Au:N/C:N/I:C/A:C

Vulnerability Summary

A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

todd miller sudo 1.7.2

redhat enterprise linux 5

Vendor Advisories

Synopsis Moderate: sudo security and bug fix update Type/Severity Security Advisory: Moderate Topic An updated sudo package that fixes one security issue and several bugs isnow available for Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact ...