CVE-2012-1088
published 2014-02-15CVE-2012-1088: iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2)…
PriorityP49low3.3CVSS 2.0
AVLACMAuNCNIPAP
EPSS
0.35%
27.9th percentile
iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| iproute2_project | iproute2 | <= 3.2.0 | — |
| iproute2_project | iproute2 | — | — |
| iproute2_project | iproute2 | — | — |
| iproute2_project | iproute2 | >= 0 < 3.12.0-2 | 3.12.0-2 |
CVSS provenance
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
iproute: multiple insecure temporary file use issues
vendor_redhat·2012-02-15·CVSS 3.3
CVE-2012-1088 [LOW] CWE-377 iproute: multiple insecure temporary file use issues
iproute: multiple insecure temporary file use issues
iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script.
Statement: These issues only affect a script used during package build and do not affect binary iproute packages shipped with Red Hat Enterprise Linux. Therefore, they are not planned to be addressed in iproute packages in Red Hat Enterprise Linux 5 and 6, they are only planned to be addressed in the future Red Hat Enterprise Linux versions.
Package: iproute (Red Hat Enterprise Linux 4) - Will not fix
Package: iproute (Red Hat Enterprise Linux 5) - Will not fix
Package: iproute (Red Hat Enterprise Linux 6) - Will not fix
GHSA
GHSA-3wfr-9gjx-63gf: iproute2 before 3
ghsa_unreviewed·2022-05-17
CVE-2012-1088 [LOW] CWE-59 GHSA-3wfr-9gjx-63gf: iproute2 before 3
iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script.
OSV
CVE-2012-1088: iproute2 before 3
osv·2014-02-15·CVSS 3.3
CVE-2012-1088 [LOW] CVE-2012-1088: iproute2 before 3
iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/shemminger/iproute2.git%3Ba=commit%3Bh=20ed7b24df05eadf83168d1d0ce0052a31380928http://git.kernel.org/?p=linux/kernel/git/shemminger/iproute2.git%3Ba=commit%3Bh=e557d1ac3a156ba7521ba44b0b412af4542f83f8http://marc.info/?l=bugtraq&m=139447903326211&w=2https://bugzilla.redhat.com/show_bug.cgi?id=797878http://git.kernel.org/?p=linux/kernel/git/shemminger/iproute2.git%3Ba=commit%3Bh=20ed7b24df05eadf83168d1d0ce0052a31380928http://git.kernel.org/?p=linux/kernel/git/shemminger/iproute2.git%3Ba=commit%3Bh=e557d1ac3a156ba7521ba44b0b412af4542f83f8http://marc.info/?l=bugtraq&m=139447903326211&w=2https://bugzilla.redhat.com/show_bug.cgi?id=797878
2014-02-15
Published