CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:L/Au:N/C:P/I:P/A:P
AI Score
Confidence
High
EPSS
Percentile
5.1%
ksymoops-gznm script in Mandrake Linux 9.1 through 10.0, and Corporate Server 2.1, allows local users to delete arbitrary files via a symlink attack on files in /tmp.
Vendor | Product | Version | CPE |
---|---|---|---|
gnu | ksymoops | 2.4.5 | cpe:2.3:a:gnu:ksymoops:2.4.5:*:*:*:*:*:*:* |
gnu | ksymoops | 2.4.8 | cpe:2.3:a:gnu:ksymoops:2.4.8:*:*:*:*:*:*:* |
gnu | ksymoops | 2.4.9 | cpe:2.3:a:gnu:ksymoops:2.4.9:*:*:*:*:*:*:* |
mandrakesoft | mandrake_linux | 9.1 | cpe:2.3:o:mandrakesoft:mandrake_linux:9.1:*:*:*:*:*:*:* |
mandrakesoft | mandrake_linux | 9.1 | cpe:2.3:o:mandrakesoft:mandrake_linux:9.1:*:ppc:*:*:*:*:* |
mandrakesoft | mandrake_linux | 9.2 | cpe:2.3:o:mandrakesoft:mandrake_linux:9.2:*:*:*:*:*:*:* |
mandrakesoft | mandrake_linux | 9.2 | cpe:2.3:o:mandrakesoft:mandrake_linux:9.2:*:amd64:*:*:*:*:* |
mandrakesoft | mandrake_linux | 10.0 | cpe:2.3:o:mandrakesoft:mandrake_linux:10.0:*:*:*:*:*:*:* |
mandrakesoft | mandrake_linux | 10.0 | cpe:2.3:o:mandrakesoft:mandrake_linux:10.0:*:amd64:*:*:*:*:* |
mandrakesoft | mandrake_linux_corporate_server | 2.1 | cpe:2.3:o:mandrakesoft:mandrake_linux_corporate_server:2.1:*:*:*:*:*:*:* |