6.9

CVE-2009-1893

The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file, related to the "dhcpd -t" command.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Version 3.0
Redhat ≫ Enterprise Linux Version 3.0 Edition as
Redhat ≫ Enterprise Linux Version 3.0 Edition es
Redhat ≫ Enterprise Linux Version 3.0 Edition ws
Isc ≫ Dhcp Version 3.0.1 Update rc1
Isc ≫ Dhcp Version 3.0.1 Update rc10
Isc ≫ Dhcp Version 3.0.1 Update rc11
Isc ≫ Dhcp Version 3.0.1 Update rc12
Isc ≫ Dhcp Version 3.0.1 Update rc13
Isc ≫ Dhcp Version 3.0.1 Update rc14
Isc ≫ Dhcp Version 3.0.1 Update rc2
Isc ≫ Dhcp Version 3.0.1 Update rc5
Isc ≫ Dhcp Version 3.0.1 Update rc6
Isc ≫ Dhcp Version 3.0.1 Update rc7
Isc ≫ Dhcp Version 3.0.1 Update rc8
Isc ≫ Dhcp Version 3.0.1 Update rc9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.6% 0.441
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

http://secunia.com/advisories/35831
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2009-1154.html
Vendor Advisory
http://securitytracker.com/id?1022554
http://www.securityfocus.com/bid/35670
https://bugzilla.redhat.com/show_bug.cgi?id=510024
https://exchange.xforce.ibmcloud.com/vulnerabilities/51718
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11597
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6440