CVE-2013-4157Link Following in Redhat Storage Server

Severity
3.6LOWNVD
EPSS
0.0%
top 90.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 4
Latest updateMay 17

Description

Red Hat Storage 2.0 allows local users to overwrite arbitrary files via a symlink attack on the (1) e, (2) local-bricks.list, (3) bricks.err, or (4) limits.conf files in /tmp.

CVSS vector

AV:L/AC:L/C:N/I:P/A:PExploitability: 3.9 | Impact: 4.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m923-rj4w-wvh7: Red Hat Storage 22022-05-17
CVEList
CVE-2013-4157: Red Hat Storage 22013-10-04

📋Vendor Advisories

1
Red Hat
2.0: appliance-base / redhat-storage-server /tmp file creation vuln2013-09-04

💬Community

1
Bugzilla
CVE-2013-4157 Red Hat Storage Server 2.0: appliance-base / redhat-storage-server /tmp file creation vuln2013-07-20
CVE-2013-4157 — Link Following in Redhat Storage Server | cvebase