CVE-2013-0265
Published: 13 February 2013
The redirect_stderr function in xnbd_common.c in xnbd-server and xndb-wrapper in xNBD 0.1.0 allow local users to overwrite arbitrary files via a symlink attack on /tmp/xnbd.log.
Priority
Status
Package | Release | Status |
---|---|---|
xnbd
Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Does not exist
|
|
oneiric |
Ignored
(end of life)
|
|
precise |
Ignored
(end of life)
|
|
quantal |
Ignored
(end of life)
|
|
raring |
Ignored
(end of life)
|
|
saucy |
Ignored
(end of life)
|
|
trusty |
Does not exist
(trusty was not-affected [0.2.0~rc2-hg1-abf8cc7a1ab0-2])
|
|
upstream |
Released
(0.1.0-pre-hg20-e75b93a47722-3, 0.2.0~rc2-hg1-abf8cc7a1ab0-1)
|
|
utopic |
Ignored
(end of life)
|
|
vivid |
Ignored
(end of life)
|
|
wily |
Ignored
(end of life)
|
|
xenial |
Not vulnerable
(0.3.0-1ubuntu1)
|
|
yakkety |
Not vulnerable
(0.3.0-1ubuntu1)
|
|
zesty |
Not vulnerable
|
|
This vulnerability is mitigated in part by the use of symlink restrictions in Ubuntu. |