CVE-2011-0012
published 2011-04-18CVE-2011-0012: The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows local users to overwrite arbitrary files via a symlink attack on the…
PriorityP47low3.3CVSS 2.0
AVLACMAuNCNIPAP
EPSS
0.33%
25.3th percentile
The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows local users to overwrite arbitrary files via a symlink attack on the usbrdrctl log file, which has a predictable name.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | spice-xpi | — | — |
| redhat | spice-xpi | — | — |
| redhat | spice-xpi | — | — |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pp7j-p833-2h5r: The SPICE Firefox plug-in (spice-xpi) 2
ghsa_unreviewed·2022-05-03
CVE-2011-0012 [LOW] CWE-59 GHSA-pp7j-p833-2h5r: The SPICE Firefox plug-in (spice-xpi) 2
The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows local users to overwrite arbitrary files via a symlink attack on the usbrdrctl log file, which has a predictable name.
Red Hat
spice-xpi: symlink attack on usbrdrctl log file
vendor_redhat·2011-04-07·CVSS 3.3
CVE-2011-0012 [LOW] spice-xpi: symlink attack on usbrdrctl log file
spice-xpi: symlink attack on usbrdrctl log file
The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows local users to overwrite arbitrary files via a symlink attack on the usbrdrctl log file, which has a predictable name.
No detection rules found.
No public exploits indexed.
http://www.redhat.com/support/errata/RHSA-2011-0426.htmlhttp://www.securityfocus.com/bid/47269http://www.securitytracker.com/id?1025304http://www.vupen.com/english/advisories/2011/0899https://bugzilla.redhat.com/show_bug.cgi?id=639869http://www.redhat.com/support/errata/RHSA-2011-0426.htmlhttp://www.securityfocus.com/bid/47269http://www.securitytracker.com/id?1025304http://www.vupen.com/english/advisories/2011/0899https://bugzilla.redhat.com/show_bug.cgi?id=639869
2011-04-18
Published