CVE-2012-5303: Medium severity monkey project vulnerability
Published Oct 5, 2012
·Updated
Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathname different from the default /var/run/monkey.pid pathname.
Affected Software
1 affected component
Monkey-project Monkey=0.9.3
Event History
Oct 5, 2012
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5303?
CVE-2012-5303 is classified as a medium severity vulnerability due to the potential local file overwriting risk.
2
How do I fix CVE-2012-5303?
To mitigate CVE-2012-5303, ensure proper permissions are set on the PID file and avoid symbolic links to control access.
3
Who is affected by CVE-2012-5303?
CVE-2012-5303 affects users running Monkey HTTP Daemon version 0.9.3.
4
What type of vulnerability is CVE-2012-5303?
CVE-2012-5303 is a local file overwrite vulnerability caused by a symlink attack.
5
Can CVE-2012-5303 be exploited remotely?
CVE-2012-5303 requires local access, so it cannot be exploited remotely.