3.3
CVSSv2

CVE-2014-3986

Published: 08/06/2014 Updated: 09/06/2014
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

include/tests_webservers in Lynis prior to 1.5.5 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.*.unsorted file with an easily determined name.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisofy lynis

cisofy lynis 1.5.2

cisofy lynis 1.5.0

cisofy lynis 1.5.3

cisofy lynis 1.5.1

Vendor Advisories

Debian Bug report logs - #751083 lynis: CVE-2014-3986 Package: lynis; Maintainer for lynis is Francisco Manuel Garcia Claramonte <francisco@debianorg>; Source for lynis is src:lynis (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Tue, 10 Jun 2014 07:09:01 UTC Severity: grave Tags: secur ...