vendor:
Red Hat Enterprise Linux, Fedora
by:
Unknown
5.5
CVSS
MEDIUM
Unreliable sticky-bit in /tmp directory
CWE
Product Name: Red Hat Enterprise Linux, Fedora
Affected Version From: All known versions of policycore-utils
Affected Version To: All known versions of policycore-utils
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
2011
Developers should not rely on the stickiness of /tmp on Red Hat Linux
Unprivileged users can effectively remove the sticky-bit from the system /tmp directory, making it unsafe to rely on the stickiness of /tmp on Red Hat Linux systems.
Mitigation:
Developers and system administrators should not rely on the stickiness of /tmp on Red Hat Linux systems. Alternative security measures should be implemented.