vendor:
Enterprise Linux
by:
zen-parse
7.2
CVSS
HIGH
Race Condition
362
CWE
Product Name: Enterprise Linux
Affected Version From: Redhat 7.0
Affected Version To: Redhat 7.0
Patch Exists: YES
Related CWE: N/A
CPE: o:redhat:enterprise_linux:7.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2001
Crontab tmp file race condition
A race condition vulnerability exists in the swap file mechanism used by the 'vim' program. The error occurs when a swap file name for a file being opened is symbolically linked to a non-existent file. By conjecturing the name of a file to be edited by another user, it may be possible for a local user to create a malicious symbolic link to a non-existent file. This could cause the new target file to be created with the permissions of the user running vim.
Mitigation:
Ensure that the swap file mechanism is secure and that users are not able to create malicious symbolic links.