First published: Tue Feb 05 2013(Updated: )
(1) installer/basedefs.py and (2) modules/ospluginutils.py in PackStack allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Essex | ||
OpenStack Folsom |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0261 is classified as a moderate severity vulnerability due to its potential impact on file overwriting via symlink attacks.
To remediate CVE-2013-0261, ensure that the affected software versions are upgraded to non-vulnerable releases or apply the relevant patches provided by the maintainers.
CVE-2013-0261 affects OpenStack Essex and OpenStack Folsom versions.
CVE-2013-0261 requires local access to the system for exploitation, making it less of a threat for remote attackers.
CVE-2013-0261 facilitates symlink attacks allowing local users to overwrite arbitrary files.