[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2015-4156Date: (C)2015-06-04   (M)2023-12-22


GNU Parallel before 20150522 (Nepal), when using (1) --cat or (2) --fifo with --sshlogin, allows local users to write to arbitrary files via a symlink attack on a temporary file.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.6
Exploit Score: 3.9
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
BID-74961
http://lists.gnu.org/archive/html/parallel/2015-04/msg00045.html
http://lists.gnu.org/archive/html/parallel/2015-05/msg00024.html
openSUSE-SU-2015:0968

CPE    2
cpe:/a:gnu:parallel
cpe:/o:opensuse:opensuse:13.1
CWE    1
CWE-59

© SecPod Technologies