CVE-2010-2794: Low severity redhat Spice-xpi vulnerability
Spice-xpi uses predictable name for it's log file which a malicious user could use to overwrite arbitrary files via a symlink attack, with the privileges of the user running spice-xpi.
Other sources
The SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to overwrite arbitrary files via a symlink attack on an unspecified log file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2794?
CVE-2010-2794 is classified as a moderate severity vulnerability due to the potential for local users to overwrite arbitrary files.
How do I fix CVE-2010-2794?
To fix CVE-2010-2794, upgrade to a later version of the Spice-xpi plug-in that addresses the symlink vulnerability.
Who is affected by CVE-2010-2794?
CVE-2010-2794 affects users of the Spice-xpi plug-in version 2.2 on systems running Firefox.
What type of attack does CVE-2010-2794 expose users to?
CVE-2010-2794 exposes users to a symlink attack that can lead to arbitrary file overwriting.
Can CVE-2010-2794 be exploited remotely?
No, CVE-2010-2794 requires local access to exploit the vulnerability.