CVE-2011-3618
published 2019-11-12CVE-2011-3618: atop: symlink attack possible due to insecure tempfile handling
PriorityP434high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.41%
33.7th percentile
atop: symlink attack possible due to insecure tempfile handling
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atop | atop | — | — |
| atop | atop | >= 0 < 1.23-1.1 | 1.23-1.1 |
| atop | atop | >= 0 < 1.23-1.1 | 1.23-1.1 |
| atop | atop | >= 0 < 1.23-1.1 | 1.23-1.1 |
| atop | atop | >= 0 < 1.23-1.1 | 1.23-1.1 |
| debian | atop | < atop 1.23-1.1 (bookworm) | atop 1.23-1.1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-95pq-v592-p42v: atop: symlink attack possible due to insecure tempfile handling
ghsa_unreviewed·2022-04-22
CVE-2011-3618 [MEDIUM] GHSA-95pq-v592-p42v: atop: symlink attack possible due to insecure tempfile handling
atop: symlink attack possible due to insecure tempfile handling
OSV
CVE-2011-3618: atop: symlink attack possible due to insecure tempfile handling
osv·2019-11-12·CVSS 7.8
CVE-2011-3618 [HIGH] CVE-2011-3618: atop: symlink attack possible due to insecure tempfile handling
atop: symlink attack possible due to insecure tempfile handling
Debian
CVE-2011-3618: atop - atop: symlink attack possible due to insecure tempfile handling
vendor_debian·2011·CVSS 7.8
CVE-2011-3618 [HIGH] CVE-2011-3618: atop - atop: symlink attack possible due to insecure tempfile handling
atop: symlink attack possible due to insecure tempfile handling
Scope: local
bookworm: resolved (fixed in 1.23-1.1)
bullseye: resolved (fixed in 1.23-1.1)
forky: resolved (fixed in 1.23-1.1)
sid: resolved (fixed in 1.23-1.1)
trixie: resolved (fixed in 1.23-1.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3618 atop: Insecure temporary file use flaw by management of runtime data [epel-4]
bugzilla·2011-10-12·CVSS 7.8
CVE-2011-3618 [HIGH] CVE-2011-3618 atop: Insecure temporary file use flaw by management of runtime data [epel-4]
CVE-2011-3618 atop: Insecure temporary file use flaw by management of runtime data [epel-4]
epel-4 tracking bug for atop: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
atop-1.26-1.el4.1 has been submitted as an update for Fedora EPEL 4.
https://admin.fedoraproject.org/updates/atop-1.26-1.el4.1
---
Package atop-1.26-1.el4.1:
* should fix your issue,
* was pushed to the Fedora EPEL 4 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=epel-testing atop-1.26-1.el4.1'
as soon as you are able to.
Please go to the following url:
https://adm
Bugzilla
CVE-2011-3618 atop: Insecure temporary file use flaw by management of runtime data [fedora-all]
bugzilla·2011-10-12·CVSS 7.8
CVE-2011-3618 [HIGH] CVE-2011-3618 atop: Insecure temporary file use flaw by management of runtime data [fedora-all]
CVE-2011-3618 atop: Insecure temporary file use flaw by management of runtime data [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=745479
Please note: this i
Bugzilla
CVE-2011-3618 atop: Insecure temporary file use flaw by management of runtime data
bugzilla·2011-10-12·CVSS 7.8
CVE-2011-3618 [HIGH] CVE-2011-3618 atop: Insecure temporary file use flaw by management of runtime data
CVE-2011-3618 atop: Insecure temporary file use flaw by management of runtime data
An insecure temporary file use flaw was found in the way atop, an advanced interactive monitor to view the load on system and process level, has kept its temporary runtime data in temporary files. A local attacker could use this flaw to conduct symlink attacks (make atop to remove file named 'atop.acct' in the linked-to directory).
References:
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=622794
[2] http://www.openwall.com/lists/oss-security/2011/10/09/5
(CVE request)
[3] http://www.openwall.com/lists/oss-security/2011/10/10/10
(CVE assignment)
Patches applied by Debian Linux distribution:
[5] http://mozilla.mirror.pop-sc.rnp.br/mirror/Debian/pool/main/a/atop/atop_1.23-1+lenny1.diff.gz
(relevant ch
Bugzilla
CVE-2011-3618 atop: Insecure temporary file use flaw by management of runtime data [epel-5]
bugzilla·2011-10-12·CVSS 7.8
CVE-2011-3618 [HIGH] CVE-2011-3618 atop: Insecure temporary file use flaw by management of runtime data [epel-5]
CVE-2011-3618 atop: Insecure temporary file use flaw by management of runtime data [epel-5]
epel-5 tracking bug for atop: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
atop-1.26-1.el5.1 has been submitted as an update for Fedora EPEL 5.
https://admin.fedoraproject.org/updates/atop-1.26-1.el5.1
---
Package atop-1.26-1.el5.1:
* should fix your issue,
* was pushed to the Fedora EPEL 5 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=epel-testing atop-1.26-1.el5.1'
as soon as you are able to.
Please go to the following url:
https://adm
https://access.redhat.com/security/cve/cve-2011-3618https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3618https://security-tracker.debian.org/tracker/CVE-2011-3618https://access.redhat.com/security/cve/cve-2011-3618https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-3618https://security-tracker.debian.org/tracker/CVE-2011-3618
2019-11-12
Published