cbcvebase.
CVE-2009-4135
published 2009-12-11

CVE-2009-4135: The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree…

PriorityP418medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.38%
30.1th percentile
The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiancoreutils
fedoraprojectfedora
fedoraprojectfedora
gnucoreutils
gnucoreutils
gnucoreutils
gnucoreutils
gnucoreutils
gnucoreutils
gnucoreutils
gnucoreutils
gnucoreutils
gnucoreutils
gnucoreutils
gnucoreutils
gnucoreutils
gnucoreutils
gnucoreutils
gnucoreutils
gnucoreutils
gnucoreutils
gnucoreutils

CVSS provenance

nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4LOW
vendor_redhat4.4MEDIUM
vendor_ubuntu4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.