CVE-2011-3602: Path Traversal
Directory traversal vulnerability in device-linux.c in the router advertisement daemon (radvd) before 1.8.2 allows local users to overwrite arbitrary files, and remote attackers to overwrite certain files, via a .. (dot dot) in an interface name. NOTE: this can be leveraged with a symlink to overwrite arbitrary files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3602?
CVE-2011-3602 has a moderate severity rating due to its potential for local user file overwriting and remote file manipulation.
How do I fix CVE-2011-3602?
To fix CVE-2011-3602, upgrade the router advertisement daemon to version 1.8.2 or later.
Who is affected by CVE-2011-3602?
CVE-2011-3602 affects users of Litech Router Advertisement Daemon versions prior to 1.8.2.
What types of attacks can CVE-2011-3602 enable?
CVE-2011-3602 can enable local and remote attackers to overwrite arbitrary files on the affected system.
Is there a workaround for CVE-2011-3602?
No officially recommended workaround exists for CVE-2011-3602 aside from upgrading to the patched version.