CVE-2014-3982
Published Jun 8, 2014
Last updated 10 years ago
Overview
- Description
- include/tests_webservers in Lynis before 1.5.5 on AIX allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.##### file.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 3.3
- Impact score
- 4.9
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:N/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-59
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cisofy:lynis:*:*:*:*:*:aix:*:*", "vulnerable": true, "matchCriteriaId": "98E5E36B-D438-4D01-BE9A-16A57031160C", "versionEndIncluding": "1.5.4" }, { "criteria": "cpe:2.3:a:cisofy:lynis:1.5.0:*:*:*:*:aix:*:*", "vulnerable": true, "matchCriteriaId": "2AEABCD5-1E54-4ED2-94C2-306A4E2D072C" }, { "criteria": "cpe:2.3:a:cisofy:lynis:1.5.1:*:*:*:*:aix:*:*", "vulnerable": true, "matchCriteriaId": "84B2EEC1-3068-42D8-B43D-E5620EE271A8" }, { "criteria": "cpe:2.3:a:cisofy:lynis:1.5.2:*:*:*:*:aix:*:*", "vulnerable": true, "matchCriteriaId": "A4C28BCB-0CA0-4B8A-829D-E744D437D5CC" }, { "criteria": "cpe:2.3:a:cisofy:lynis:1.5.3:*:*:*:*:aix:*:*", "vulnerable": true, "matchCriteriaId": "5A16F7D6-4250-4191-9802-BD457D711B8D" } ], "operator": "OR" } ] } ]