Lucene search

K
cve[email protected]CVE-2013-0164
HistoryFeb 24, 2013 - 10:55 p.m.

CVE-2013-0164

2013-02-2422:55:01
CWE-264
web.nvd.nist.gov
28
nvd
cve-2013-0164
information security
red hat openshift origin
symlink attack
temporary file

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.

Affected configurations

NVD
Node
redhatopenshiftRange1.0-enterprise
OR
redhatopenshift_originMatch1.0.5

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%