ID | CVE-2013-4419 | ||||||
Sažetak | The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance. | ||||||
Reference | |||||||
CVSS |
|
||||||
Pristup |
|
||||||
Impact |
|
||||||
CVSS vektor | AV:A/AC:H/Au:N/C:C/I:C/A:C | ||||||
Zadnje važnije ažuriranje | 13-12-2018 - 17:57 | ||||||
Objavljeno | 05-11-2013 - 20:55 |