6.6
CVSSv2

CVE-2019-12779

Published: 07/06/2019 Updated: 03/07/2021
CVSS v2 Base Score: 6.6 | Impact Score: 9.2 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 587
Vector: AV:L/AC:L/Au:N/C:N/I:C/A:C

Vulnerability Summary

libqb prior to 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

clusterlabs libqb

Vendor Advisories

Debian Bug report logs - #927159 libqb: CVE-2019-12779: Insecure Temporary Files Package: src:libqb; Maintainer for src:libqb is Debian HA Maintainers <debian-ha-maintainers@listsaliothdebianorg>; Reported by: Ferenc Wágner <wferi@debianorg> Date: Mon, 15 Apr 2019 18:12:02 UTC Severity: grave Tags: patch, securi ...
Synopsis Moderate: libqb security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for libqb is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base s ...
Synopsis Moderate: libqb security update Type/Severity Security Advisory: Moderate Topic An update for libqb is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, which ...
A flaw was found in libqb Insecure handling of temporary files could be exploited by a local attacker to overwrite privileged system files Upstream issue: githubcom/ClusterLabs/libqb/issues/338 ...