cbcvebase.
CVE-2012-1174
published 2012-07-12

CVE-2012-1174: The rm_rf_children function in util.c in the systemd-logind login manager in systemd before 44, when logging out, allows local users to delete arbitrary files…

PriorityP411low3.3CVSS 2.0
AVLACMAuNCNIPAP
EPSS
0.32%
24.7th percentile
The rm_rf_children function in util.c in the systemd-logind login manager in systemd before 44, when logging out, allows local users to delete arbitrary files via a symlink attack on unspecified files, related to "particular records related with user session."

Affected

6 ranges
VendorProductVersion rangeFixed in
debiansystemd< systemd 44-1 (bookworm)systemd 44-1 (bookworm)
linuxsystemd
systemd_projectsystemd>= 0 < 44-144-1
systemd_projectsystemd>= 0 < 44-144-1
systemd_projectsystemd>= 0 < 44-144-1
systemd_projectsystemd>= 0 < 44-144-1

CVSS provenance

nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv3.3LOW
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.