CVE-2012-3440

Published Aug 8, 2012

Last updated 2 years ago

Overview

Description
A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file.
Source
secalert@redhat.com
NVD status
Modified

Social media

Hype score
Not currently trending

Risk scores

CVSS 2.0

Type
Primary
Base score
5.6
Impact score
9.2
Exploitability score
1.9
Vector string
AV:L/AC:H/Au:N/C:N/I:C/A:C

Weaknesses

nvd@nist.gov
CWE-59

Evaluator

Comment
Additional information: https://rhn.redhat.com/errata/RHSA-2012-1149.html
Impact
-
Solution
-

Configurations