Cisofy

Lynis

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Veröffentlicht 18.06.2020 18:15:10
  • Zuletzt bearbeitet 21.11.2024 04:24:05

In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis server. Although no data can be extracted by knowing t...

  • EPSS 0.05%
  • Veröffentlicht 18.06.2020 18:15:10
  • Zuletzt bearbeitet 21.11.2024 05:02:04

CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and could be bypassed locally. Because of the race, an unprivileged attack...

  • EPSS 0.07%
  • Veröffentlicht 08.06.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Unspecified tests in Lynis before 2.5.0 allow local users to write to arbitrary files or possibly gain privileges via a symlink attack on a temporary file.

  • EPSS 0.05%
  • Veröffentlicht 08.06.2014 18:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

include/tests_webservers in Lynis before 1.5.5 on AIX allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.##### file.

  • EPSS 0.05%
  • Veröffentlicht 08.06.2014 18:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

include/tests_webservers in Lynis before 1.5.5 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.*.unsorted file with an easily determined name.