CVE-2014-3986: Low severity CISOfy Lynis vulnerability
Published Jun 8, 2014
·Updated
include/testswebservers in Lynis before 1.5.5 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis..unsorted file with an easily determined name.
Affected Software
5 affected components
CISOfy Lynis<=1.5.4
CISOfy Lynis=1.5.0
CISOfy Lynis=1.5.1
CISOfy Lynis=1.5.2
CISOfy Lynis=1.5.3
Event History
Jun 8, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3986?
CVE-2014-3986 is considered to be of medium severity due to the risk of local users exploiting the symlink vulnerability to overwrite arbitrary files.
2
How do I fix CVE-2014-3986?
To fix CVE-2014-3986, upgrade Lynis to version 1.5.5 or later, which mitigates the symlink attack.
3
Who is affected by CVE-2014-3986?
Users of Lynis versions prior to 1.5.5 are affected by CVE-2014-3986.
4
What are the impacts of CVE-2014-3986?
The impact of CVE-2014-3986 includes potential unauthorized access and modification of sensitive files by local users.
5
When was CVE-2014-3986 discovered?
CVE-2014-3986 was publicly disclosed in June 2014.