First published: Thu Feb 05 2009(Updated: )
alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/alsa-driver | ||
ALSA (Advanced Linux Sound Architecture) | >=1.0.19<1.0.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0035 is considered a medium severity vulnerability due to its ability to allow local users to overwrite arbitrary files.
To mitigate CVE-2009-0035, ensure you limit user access to the vulnerable scripts and consider upgrading to a patched version of alsa-utils.
CVE-2009-0035 affects alsa-utils version 1.0.19 and later, specifically targeting systems using ALSA on Linux.
No, CVE-2009-0035 requires local access to the system for exploitation through a symlink attack.
A symlink attack in CVE-2009-0035 involves tricking a program into writing data to arbitrary files through symbolic links.