CVE-2014-3982: Low severity CISOfy Lynis Aix vulnerability
Published Jun 8, 2014
·Updated
include/testswebservers in Lynis before 1.5.5 on AIX allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.##### file.
Affected Software
5 affected components
CISOfy Lynis Aix<=1.5.4
CISOfy Lynis Aix=1.5.0
CISOfy Lynis Aix=1.5.1
CISOfy Lynis Aix=1.5.2
CISOfy Lynis Aix=1.5.3
Remediation
Patch Available
Event History
Jun 8, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3982?
CVE-2014-3982 has a moderate severity rating due to the potential for local users to overwrite arbitrary files.
2
How do I fix CVE-2014-3982?
To fix CVE-2014-3982, upgrade Lynis to version 1.5.5 or later.
3
Which versions of Lynis are affected by CVE-2014-3982?
CVE-2014-3982 affects Lynis versions up to and including 1.5.4.
4
What type of attack does CVE-2014-3982 involve?
CVE-2014-3982 involves a symlink attack that allows local users to overwrite files.
5
Can CVE-2014-3982 be exploited remotely?
No, CVE-2014-3982 can only be exploited by local users on the system.