CVE-2012-0871 — Link Following in Project Systemd
Severity
6.3MEDIUMNVD
EPSS
0.1%
top 68.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 18
Latest updateMay 13
Description
The session_link_x11_socket function in login/logind-session.c in systemd-logind in systemd, possibly 37 and earlier, allows local users to create or overwrite arbitrary files via a symlink attack on the X11 user directory in /run/user/.
CVSS vector
AV:L/AC:M/C:N/I:C/A:CExploitability: 3.4 | Impact: 9.2
Affected Packages3 packages
🔴Vulnerability Details
3📋Vendor Advisories
1Debian▶
CVE-2012-0871: systemd - The session_link_x11_socket function in login/logind-session.c in systemd-logind...↗2012