CVE-2011-4617Link Following in Virtualenv

CWE-59Link Following9 documents6 sources
Severity
1.2LOWNVD
EPSS
0.0%
top 88.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateMay 17

Description

virtualenv.py in virtualenv before 1.5 allows local users to overwrite arbitrary files via a symlink attack on a certain file in /tmp/.

CVSS vector

AV:L/AC:H/C:N/I:P/A:NExploitability: 1.9 | Impact: 2.9

Affected Packages2 packages

NVDpython/virtualenv1.4.9+26

🔴Vulnerability Details

4
GHSA
Virtualenv Allows Symlink Attack on /tmp/2022-05-17
OSV
Virtualenv Allows Symlink Attack on /tmp/2022-05-17
CVEList
CVE-2011-4617: virtualenv2011-12-31
OSV
CVE-2011-4617: virtualenv2011-12-31

📋Vendor Advisories

1
Debian
CVE-2011-4617: python-virtualenv - virtualenv.py in virtualenv before 1.5 allows local users to overwrite arbitrary...2011

💬Community

3
Bugzilla
CVE-2011-4617 python-virtualenv XSS [fedora-all]2012-01-03
Bugzilla
CVE-2011-4617 python-virtualenv XSS [epel-all]2012-01-03
Bugzilla
CVE-2011-4617 python-virtualenv XSS2011-12-19
CVE-2011-4617 — Link Following in Virtualenv | cvebase