6.9

CVE-2008-1570

Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating the LOCKPATH directory, then modifying it after the symbolic link check occurs.  NOTE: this is due to an incomplete fix for CVE-2008-1569.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Policyd-weightPolicyd-weight Version0.1.14_beta-14
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.128
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

http://secunia.com/advisories/29738
http://security.gentoo.org/glsa/glsa-200804-11.xml
http://www.osvdb.org/43888
https://bugs.gentoo.org/show_bug.cgi?id=214403
https://exchange.xforce.ibmcloud.com/vulnerabilities/41570