4.7
CVSSv3

CVE-2013-4235

Published: 03/12/2019 Updated: 13/02/2023
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 4.7 | Impact Score: 3.6 | Exploitability Score: 1
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian shadow -

debian debian linux 8.0

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 17

fedoraproject fedora 16

redhat enterprise linux 6.0

redhat enterprise linux 5

Vendor Advisories

Debian Bug report logs - #778950 shadow: CVE-2013-4235 symbolic link race condition Package: src:shadow; Maintainer for src:shadow is Shadow package maintainers <pkg-shadow-devel@listsaliothdebianorg>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Sun, 22 Feb 2015 02:39:01 UTC Severity: normal Tags: sec ...