First published: Mon Jul 22 2013(Updated: )
ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp file vulnerabilities" in (1) tcp/tcp_connect.c, (2) server/eventscript.c, (3) tools/ctdb_diagnostics, (4) config/gdb_backtrace, and (5) include/ctdb_private.h.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ctdb project ctdb | <=2.2 | |
ctdb project ctdb | =2.0 | |
ctdb project ctdb | =2.1 | |
openSUSE | =12.3 | |
openSUSE | =13.1 | |
Mageia | =3.0 | |
Mageia | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2013-4159 is not explicitly rated, but it relates to several temporary file vulnerabilities that can lead to security risks.
To fix CVE-2013-4159, upgrade to a version of ctdb that is above 2.2, specifically 2.3 or later.
OpenSUSE versions 12.3 and 13.1 are affected by CVE-2013-4159.
CVE-2013-4159 specifically affects the ctdb software in the mentioned versions.
The implications of CVE-2013-4159 relate to potential unauthorized access or modification due to insecure temporary file handling.