First published: Mon Mar 31 2008(Updated: )
Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating the LOCKPATH directory, then modifying it after the symbolic link check occurs. NOTE: this is due to an incomplete fix for CVE-2008-1569.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/policyd-weight | 0.1.15.2-12 0.1.15.2-12.1 | |
Policyd-weight | =0.1.14_beta-14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.