|
|
| |
|
| |
sudo: symlink attack
| Package(s): | sudo |
CVE #(s): | CVE-2012-3440
|
| Created: | August 8, 2012 |
Updated: | August 9, 2012 |
| Description: |
From the Red Hat advisory:
An insecure temporary file use flaw was found in the sudo package's
post-uninstall script. A local attacker could possibly use this flaw to
overwrite an arbitrary file via a symbolic link attack, or modify the
contents of the "/etc/nsswitch.conf" file during the upgrade or removal of
the sudo package. |
| Alerts: |
|
( Log in to post comments)
|
|
|