Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24594
HistoryApr 10, 2020 - 12:58 a.m.

Symlink Attack

2020-04-1000:58:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.0004 Low

EPSS

Percentile

5.1%

Bash (Bourne-again shell) is the default shell for Red Hat Enterprise Linux. It was found that certain scripts bundled with the Bash documentation created temporary files in an insecure way. A malicious, local user could use this flaw to conduct a symbolic link attack, allowing them to overwrite the contents of arbitrary files accessible to the victim running the scripts.