CVE-2013-0159: High severity red hat fedora vulnerability
Michael Scherer reported that the fedora-business-cards script used /tmp/fedora-business-cards-buffer.svg as a temporary file, which could be used in symlink attacks to overwrite the contents of a file with write permissions to the person running fedora-business-cards.
Other sources
The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows local users to cause a denial of service or write to arbitrary files via a symlink attack on /tmp/fedora-business-cards-buffer.svg.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0159?
CVE-2013-0159 has a moderate severity rating, indicating potential risk for data integrity through symlink attacks.
How do I fix CVE-2013-0159?
To fix CVE-2013-0159, update to a patched version of Fedora that addresses the symlink vulnerability in the fedora-business-cards script.
Which versions of Fedora are affected by CVE-2013-0159?
CVE-2013-0159 affects Fedora versions 17 and 18.
What type of attack is associated with CVE-2013-0159?
CVE-2013-0159 is associated with symlink attacks that could result in unauthorized file overwriting.
Who reported the vulnerability CVE-2013-0159?
The vulnerability CVE-2013-0159 was reported by Michael Scherer.