| Vulnerability Name: | CVE-2016-3992 (CCN-112294) | ||||||||||||||||
| Assigned: | 2016-04-11 | ||||||||||||||||
| Published: | 2016-04-11 | ||||||||||||||||
| Updated: | 2018-10-30 | ||||||||||||||||
| Summary: | cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$ file in /tmp. | ||||||||||||||||
| CVSS v3 Severity: | 6.2 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) 5.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||
| CVSS v2 Severity: | 4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:C/A:N)
| ||||||||||||||||
| Vulnerability Type: | CWE-284 | ||||||||||||||||
| Vulnerability Consequences: | File Manipulation | ||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2016-3992 Source: SUSE Type: Third Party Advisory openSUSE-SU-2016:1741 Source: CCN Type: oss-sec Mailing List, Sun, 10 Apr 2016 00:49:22 +0200 CVE request: cronic - predictable temporary files Source: CCN Type: oss-sec Mailing List, Sun, 10 Apr 2016 10:23:11 -0400 (EDT) Re: CVE request: cronic - predictable temporary files Source: MLIST Type: UNKNOWN [oss-security] 20160410 CVE request: cronic - predictable temporary files Source: MLIST Type: UNKNOWN [oss-security] 20160410 Re: CVE request: cronic - predictable temporary files Source: CCN Type: Debian Bug report logs - 820331 cronic: CVE-2016-3992: uses very predictable temporary files Source: CONFIRM Type: Third Party Advisory https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=820331 Source: XF Type: UNKNOWN cronic-cve20163992-symlink(112294) Source: CCN Type: cronic Web site Debian Package Tracking System - cronic | ||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Denotes that component is vulnerable | ||||||||||||||||
| Oval Definitions | |||||||||||||||||
| |||||||||||||||||
| BACK | |||||||||||||||||