[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2013-1976Date: (C)2013-08-21   (M)2023-12-22


The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0, and Red Hat Enterprise Linux 5 and 6, allow local users to change the ownership of arbitrary files via a symlink attack on (a) tomcat5-initd.log, (b) tomcat6-initd.log, (c) catalina.out, or (d) tomcat7-initd.log.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.9
Exploit Score: 3.4
Impact Score: 10.0
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: COMPLETE
Integrity: COMPLETE
Availability: COMPLETE
  
Reference:
RHSA-2013:0869
RHSA-2013:0870
RHSA-2013:0871
RHSA-2013:0872
https://bugzilla.redhat.com/show_bug.cgi?id=927622
openSUSE-SU-2013:1306

CPE    3
cpe:/a:redhat:jboss_enterprise_web_server:1.0.2
cpe:/o:redhat:enterprise_linux:5
cpe:/a:redhat:jboss_enterprise_web_server:2.0.0
CWE    1
CWE-59
OVAL    7
oval:org.secpod.oval:def:1500183
oval:org.secpod.oval:def:202890
oval:org.secpod.oval:def:1500182
oval:org.secpod.oval:def:501062
...

© SecPod Technologies