vendor:
Enterprise Linux
by:
Gabriel Maggiotti
7.2
CVSS
HIGH
Denial of Service
20
CWE
Product Name: Enterprise Linux
Affected Version From: RedHat 5.1
Affected Version To: RedHat 7.1
Patch Exists: YES
Related CWE: N/A
CPE: o:redhat:enterprise_linux:7.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2001
Samba Server r00t exploit
A problem in the Samba package could make it possible to deny service to legitimate users. Due to the insecure creation of files in the /tmp file system, it is possible for a user to create a symbolic link to other files owned by privileged users in the system, such as system device files, and write data to the files.
Mitigation:
Ensure that the /tmp directory is secure and that users cannot create symbolic links to other files owned by privileged users.