CVE-2013-4392

SOURCE - nist

Summary

systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.

EPSS Score: 0.00042 (0.052)

Common Weakness Enumeration (CWE)

SOURCE - nist

Improper Link Resolution Before File Access ('Link Following')

SOURCE - redhat

Time-of-check Time-of-use (TOCTOU) Race Condition


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/systemddebdebian12>=252.22-1~deb12u1Not yet available
debian/systemddebdebian13>=255.5-1Not yet available
debian/systemddebdebian10>=241-7~deb10u8Not yet available
debian/systemddebdebian11>=247.3-7+deb11u4Not yet available
debian/systemddebdebianunstable>=256~rc2-3Not yet available

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

3.4


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

3.3low

ubuntu

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow

redhat

CREATED


UPDATED



EXPLOITABILITY SCORE

3.4


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

3.3medium