6.3
CVE-2012-0871
- EPSS 0.15%
- Published 18.04.2014 14:55:25
- Last modified 12.04.2025 10:46:40
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on the X11 user directory in /run/user/.
Data is provided by the National Vulnerability Database (NVD)
Systemd Project ≫ Systemd Version <= 037
Systemd Project ≫ Systemd Version1
Systemd Project ≫ Systemd Version2
Systemd Project ≫ Systemd Version3
Systemd Project ≫ Systemd Version4
Systemd Project ≫ Systemd Version5
Systemd Project ≫ Systemd Version6
Systemd Project ≫ Systemd Version7
Systemd Project ≫ Systemd Version8
Systemd Project ≫ Systemd Version9
Systemd Project ≫ Systemd Version10
Systemd Project ≫ Systemd Version11
Systemd Project ≫ Systemd Version12
Systemd Project ≫ Systemd Version13
Systemd Project ≫ Systemd Version14
Systemd Project ≫ Systemd Version15
Systemd Project ≫ Systemd Version16
Systemd Project ≫ Systemd Version17
Systemd Project ≫ Systemd Version18
Systemd Project ≫ Systemd Version19
Systemd Project ≫ Systemd Version20
Systemd Project ≫ Systemd Version21
Systemd Project ≫ Systemd Version22
Systemd Project ≫ Systemd Version23
Systemd Project ≫ Systemd Version24
Systemd Project ≫ Systemd Version25
Systemd Project ≫ Systemd Version26
Systemd Project ≫ Systemd Version27
Systemd Project ≫ Systemd Version28
Systemd Project ≫ Systemd Version29
Systemd Project ≫ Systemd Version30
Systemd Project ≫ Systemd Version31
Systemd Project ≫ Systemd Version32
Systemd Project ≫ Systemd Version33
Systemd Project ≫ Systemd Version34
Systemd Project ≫ Systemd Version35
Systemd Project ≫ Systemd Version36
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.15% | 0.314 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.3 | 3.4 | 9.2 |
AV:L/AC:M/Au:N/C:N/I:C/A:C
|
CWE-59 Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.