Lucene search

K
cve[email protected]CVE-2014-3986
HistoryJun 08, 2014 - 6:55 p.m.

CVE-2014-3986

2014-06-0818:55:06
CWE-59
web.nvd.nist.gov
20
lynis
security
cve-2014-3986
file overwrite
symlink attack

3.3 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:P/A:P

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

include/tests_webservers in Lynis before 1.5.5 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.*.unsorted file with an easily determined name.

Affected configurations

NVD
Node
cisofylynisRange1.5.4
OR
cisofylynisMatch1.5.0
OR
cisofylynisMatch1.5.1
OR
cisofylynisMatch1.5.2
OR
cisofylynisMatch1.5.3

3.3 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:P/A:P

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%