| ID |
CVE-2011-2473
|
| Sažetak |
The do_dump_data function in utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to create or overwrite arbitrary files via a crafted --session-dir argument in conjunction with a symlink attack on the opd_pipe file, a different vulnerability than CVE-2011-1760. |
| Reference |
|
| CVSS |
| Base: | 6.3 |
| Impact: | 9.2 |
| Exploitability: | 3.4 |
|
| Pristup |
| Vektor | Složenost | Autentikacija |
| LOCAL |
MEDIUM |
NONE |
|
| Impact |
| Povjerljivost | Cjelovitost | Dostupnost |
| NONE |
COMPLETE |
COMPLETE |
|
| CVSS vektor |
AV:L/AC:M/Au:N/C:N/I:C/A:C |
| Zadnje važnije ažuriranje |
29-08-2017 - 01:29 |
| Objavljeno |
09-06-2011 - 21:55 |