REDHAT-BUG-875842: Low severity Performance Co-Pilot PCP vulnerability
A security flaw was found in the way Performance Co-Pilot (PCP), a framework and services to support system-level performance monitoring and performance management, performed management of its temporary files used by various services from the suite. A local attacker could use this flaw to conduct symbolic link attacks (alter or remove different system files, accessible with the privileges of the user running the PCP suite, than it was originally intended).
References: [1] https://bugzilla.novell.com/showbug.cgi?id=782967 (private)
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-875842?
The severity of REDHAT-BUG-875842 is classified as moderate due to potential local attacker exploitation.
How do I fix REDHAT-BUG-875842?
To fix REDHAT-BUG-875842, update Performance Co-Pilot (PCP) to the latest patched version provided by the vendor.
Who is affected by REDHAT-BUG-875842?
Users running Performance Co-Pilot (PCP) that utilize temporary file management services are affected by REDHAT-BUG-875842.
What type of attack can REDHAT-BUG-875842 facilitate?
REDHAT-BUG-875842 could allow a local attacker to conduct unauthorized file access or manipulation.
When was REDHAT-BUG-875842 discovered?
REDHAT-BUG-875842 was reported and documented in 2023.