Vulnerability Name: | CVE-2010-2192 (CCN-59590) | ||||||||||||||||
Assigned: | 2010-06-17 | ||||||||||||||||
Published: | 2010-06-17 | ||||||||||||||||
Updated: | 2010-06-22 | ||||||||||||||||
Summary: | The make_lockdir_name function in policy.c in pmount 0.9.18 allow local users to overwrite arbitrary files via a symlink attack on a file in /var/lock/. | ||||||||||||||||
CVSS v3 Severity: | 5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 1.9 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N) 1.6 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
2.9 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-59 | ||||||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2010-2192 Source: CCN Type: DSA 2063-1 New pmount packages fix denial of service Source: CCN Type: SA40231 pmount Insecure Lockfile Creation Security Issue Source: CONFIRM Type: UNKNOWN http://security.debian.org/pool/updates/main/p/pmount/pmount_0.9.18-2+lenny1.diff.gz Source: DEBIAN Type: Patch DSA-2063 Source: DEBIAN Type: DSA-2063 pmount -- insecure temporary file Source: CCN Type: OSVDB ID: 65630 pmount policy.c make_lockdir_name Function Temporary File Symlink Arbitrary File Overwrite Source: BID Type: UNKNOWN 40939 Source: CCN Type: BID-40939 pmount Insecure Temporary File Creation Vulnerability Source: VUPEN Type: UNKNOWN ADV-2010-1520 Source: XF Type: UNKNOWN pmount-makelockdirname-symlink(59590) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |