|
|
| |
|
| |
systemd: removal of arbitrary system files
| Package(s): | systemd |
CVE #(s): | CVE-2012-1174
|
| Created: | March 19, 2012 |
Updated: | March 26, 2012 |
| Description: |
From the Mandriva advisory:
A TOCTOU race condition was found in the way the systemd-logind
login manager
performed removal of particular records related with user session upon
user logout. A local attacker could use this flaw to conduct symbolic
link attacks, potentially leading to removal of arbitrary system files. |
| Alerts: |
|
( Log in to post comments)
|
|
|