1.9
CVSSv2

CVE-2018-19046

Published: 08/11/2018 Updated: 13/03/2019
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 4.7 | Impact Score: 3.6 | Exploitability Score: 1
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

keepalived 2.0.8 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a file with the expected name (e.g., /tmp/keepalived.data or /tmp/keepalived.stats), with read access for the attacker and write access for the keepalived process, then this potentially leaked sensitive information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

keepalived keepalived 2.0.8

Vendor Advisories

keepalived 208 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats If a local attacker had previously created a file with the expected name (eg, /tmp/keepaliveddata or /tmp/keepalivedstats), with read access for the attacker and write access for the keepalived process, then this ...