First published: Mon Mar 31 2008(Updated: )
Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating the LOCKPATH directory, then modifying it after the symbolic link check occurs. NOTE: this is due to an incomplete fix for CVE-2008-1569.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Policyd-weight Policyd-weight | =0.1.14_beta-14 | |
debian/policyd-weight | 0.1.15.2-12 0.1.15.2-12.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.