6.3

CVE-2012-0871

The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on the X11 user directory in /run/user/.

Data is provided by the National Vulnerability Database (NVD)
Systemd ProjectSystemd Version <= 037
Systemd ProjectSystemd Version1
Systemd ProjectSystemd Version2
Systemd ProjectSystemd Version3
Systemd ProjectSystemd Version4
Systemd ProjectSystemd Version5
Systemd ProjectSystemd Version6
Systemd ProjectSystemd Version7
Systemd ProjectSystemd Version8
Systemd ProjectSystemd Version9
Systemd ProjectSystemd Version10
Systemd ProjectSystemd Version11
Systemd ProjectSystemd Version12
Systemd ProjectSystemd Version13
Systemd ProjectSystemd Version14
Systemd ProjectSystemd Version15
Systemd ProjectSystemd Version16
Systemd ProjectSystemd Version17
Systemd ProjectSystemd Version18
Systemd ProjectSystemd Version19
Systemd ProjectSystemd Version20
Systemd ProjectSystemd Version21
Systemd ProjectSystemd Version22
Systemd ProjectSystemd Version23
Systemd ProjectSystemd Version24
Systemd ProjectSystemd Version25
Systemd ProjectSystemd Version26
Systemd ProjectSystemd Version27
Systemd ProjectSystemd Version28
Systemd ProjectSystemd Version29
Systemd ProjectSystemd Version30
Systemd ProjectSystemd Version31
Systemd ProjectSystemd Version32
Systemd ProjectSystemd Version33
Systemd ProjectSystemd Version34
Systemd ProjectSystemd Version35
Systemd ProjectSystemd Version36
OpensuseOpensuse Version12.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.15% 0.314
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.3 3.4 9.2
AV:L/AC:M/Au:N/C:N/I:C/A:C
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.