First published: Wed Mar 14 2012(Updated: )
A TOCTOU race condition was found in the way the systemd-logind login manager of the systemd, a system and service manager for Linux, performed removal of particular records related with user session upon user logout. A local attacker could use this flaw to conduct symbolic link attacks, potentially leading to removal of arbitrary system file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
systemd | =43 |
http://cgit.freedesktop.org/systemd/systemd/commit/?id=5ebff5337594d690b322078c512eb222d34aaa82
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-1174 has been classified with a moderate severity level due to its potential for local attacker exploitation.
To fix CVE-2012-1174, it is recommended to update the systemd package to the latest version that addresses this vulnerability.
Users of systemd version 43 are affected by CVE-2012-1174.
CVE-2012-1174 can be exploited through symbolic link attacks that target user session records during logout.
CVE-2012-1174 was reported in 2012.