6.3

CVE-2012-0871

The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on the X11 user directory in /run/user/.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Systemd Project ≫ Systemd Version <= 037
Systemd Project ≫ Systemd Version 1
Systemd Project ≫ Systemd Version 2
Systemd Project ≫ Systemd Version 3
Systemd Project ≫ Systemd Version 4
Systemd Project ≫ Systemd Version 5
Systemd Project ≫ Systemd Version 6
Systemd Project ≫ Systemd Version 7
Systemd Project ≫ Systemd Version 8
Systemd Project ≫ Systemd Version 9
Systemd Project ≫ Systemd Version 10
Systemd Project ≫ Systemd Version 11
Systemd Project ≫ Systemd Version 12
Systemd Project ≫ Systemd Version 13
Systemd Project ≫ Systemd Version 14
Systemd Project ≫ Systemd Version 15
Systemd Project ≫ Systemd Version 16
Systemd Project ≫ Systemd Version 17
Systemd Project ≫ Systemd Version 18
Systemd Project ≫ Systemd Version 19
Systemd Project ≫ Systemd Version 20
Systemd Project ≫ Systemd Version 21
Systemd Project ≫ Systemd Version 22
Systemd Project ≫ Systemd Version 23
Systemd Project ≫ Systemd Version 24
Systemd Project ≫ Systemd Version 25
Systemd Project ≫ Systemd Version 26
Systemd Project ≫ Systemd Version 27
Systemd Project ≫ Systemd Version 28
Systemd Project ≫ Systemd Version 29
Systemd Project ≫ Systemd Version 30
Systemd Project ≫ Systemd Version 31
Systemd Project ≫ Systemd Version 32
Systemd Project ≫ Systemd Version 33
Systemd Project ≫ Systemd Version 34
Systemd Project ≫ Systemd Version 35
Systemd Project ≫ Systemd Version 36
Opensuse ≫ Opensuse Version 12.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.272
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.3 3.4 9.2
AV:L/AC:M/Au:N/C:N/I:C/A:C
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

http://cgit.freedesktop.org/systemd/systemd/commit/?id=fc3c1c6e091ea16ad5600b145201ec535bbb5d7c
http://lists.opensuse.org/opensuse-security-announce/2012-02/msg00030.html
http://www.osvdb.org/79768
https://bugzilla.novell.com/show_bug.cgi?id=747154
https://bugzilla.redhat.com/show_bug.cgi?id=795853