6.2
CVSSv3

CVE-2016-3992

Published: 26/07/2016 Updated: 30/10/2018
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.2 | Impact Score: 3.6 | Exploitability Score: 2.5
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:N/I:C/A:N

Vulnerability Summary

cronic prior to 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$ file in /tmp.

Vulnerable Product Search on Vulmon Subscribe to Product

cronic project cronic 2

debian debian linux 8.0

debian debian linux 7.0

opensuse leap 42.1

opensuse opensuse 13.2

Vendor Advisories

Debian Bug report logs - #820331 cronic: CVE-2016-3992: uses very predictable temporary files Package: cronic; Maintainer for cronic is Daniel Lange <DLange@debianorg>; Source for cronic is src:cronic (PTS, buildd, popcon) Reported by: Dmitry Nezhevenko <dion@dionorgua> Date: Thu, 7 Apr 2016 13:39:02 UTC Severit ...