CVE-2011-3351: High severity openvas scanner vulnerability
Published Nov 25, 2019
·Updated
openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi integrated tool enabled. A local attacker could use this flaw to conduct symlink attacks to overwrite arbitrary files on the system.
Affected Software
2 affected components
debian/openvas-server
OpenVAS openvas-scanner<2011-09-11
Event History
Nov 25, 2019
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2011-3351?
CVE-2011-3351 is classified as a moderate severity vulnerability due to its potential for local attackers to exploit symlink attacks.
2
How do I fix CVE-2011-3351?
To fix CVE-2011-3351, upgrade to openvas-scanner version 2011-09-11 or later.
3
What type of attack does CVE-2011-3351 enable?
CVE-2011-3351 enables local attackers to perform symlink attacks to overwrite arbitrary files on the system.
4
Which software is affected by CVE-2011-3351?
CVE-2011-3351 affects openvas-scanner versions prior to 2011-09-11.
5
Is CVE-2011-3351 a remote or local vulnerability?
CVE-2011-3351 is a local vulnerability that requires access to the target system to exploit.