CVE-2013-0164
published 2013-02-24CVE-2013-0164: The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1.1 allows local users to overwrite arbitrary files via a…
PriorityP411low3.6CVSS 2.0
AVLACLAuNCNIPAP
EPSS
0.36%
28.7th percentile
The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openshift | <= 1.0 | — |
| redhat | openshift_origin | — | — |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
vendor_redhat3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pf6c-h3c9-qfmc: The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1
ghsa_unreviewed·2022-05-05
CVE-2013-0164 [LOW] GHSA-pf6c-h3c9-qfmc: The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1
The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
Red Hat
openshift-origin-port-proxy: openshift-port-proxy-cfg lockwrap() tmp file creation
vendor_redhat·2013-01-31·CVSS 3.6
CVE-2013-0164 [LOW] CWE-377 openshift-origin-port-proxy: openshift-port-proxy-cfg lockwrap() tmp file creation
openshift-origin-port-proxy: openshift-port-proxy-cfg lockwrap() tmp file creation
The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2013-0220.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=893307https://github.com/openshift/origin-server/commit/524465f70a32d0eb6bf047e6a05c76c22d52bfa2https://github.com/openshift/origin-server/pull/1136http://rhn.redhat.com/errata/RHSA-2013-0220.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=893307https://github.com/openshift/origin-server/commit/524465f70a32d0eb6bf047e6a05c76c22d52bfa2https://github.com/openshift/origin-server/pull/1136
2013-02-24
Published