CVE-2009-4135: Medium severity ubuntu vulnerability
The "distcheck" Makefile rule in coreutils 5.2.1 through to 8.1 did use unsafe (predictable) temporary directory location for performing own tasks. This might allow local attacker to conduct symlink attacks under certain circumstances.
Upstream patch: --------------- http://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=ae034822c535fa5
Credit: ------- Jim Meyering
CVE Request: ------------ http://www.openwall.com/lists/oss-security/2009/12/08/4
Other sources
The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4135?
CVE-2009-4135 is considered a medium severity vulnerability that allows local users to gain elevated privileges.
How do I fix CVE-2009-4135?
To fix CVE-2009-4135, update GNU coreutils to a version later than 8.1 or apply security patches provided by your distribution.
Which versions of GNU coreutils are affected by CVE-2009-4135?
CVE-2009-4135 affects GNU coreutils versions from 5.2.1 through 8.1.
Can CVE-2009-4135 be exploited remotely?
No, CVE-2009-4135 can only be exploited locally by logged-in users.
What impact does CVE-2009-4135 have on affected systems?
CVE-2009-4135 can lead to privilege escalation, allowing local users to execute commands with elevated privileges.