CVE-2013-4280
published 2019-11-04CVE-2013-4280: Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
EPSS
0.42%
34.1th percentile
Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_virtualization | — | — |
| redhat | storage | — | — |
| redhat | storage | — | — |
| redhat | vdsm | — | — |
| redhat | virtual_desktop_server_manager | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
vdsm: /tmp file vulnerability issues
vendor_redhat·2015-07-23·CVSS 5.5
CVE-2013-4280 [MEDIUM] vdsm: /tmp file vulnerability issues
vdsm: /tmp file vulnerability issues
Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
Statement: Red Hat Storage 2 is now in Extended Life Cycle phase of the support and maintenance life cycle. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/site/support/policy/updates/rhs
Package: vdsm (Red Hat Enterprise Virtualization 3) - Affected
Package: vdsm (Red Hat Storage 2.0) - Will not fix
Package: vdsm (Red Hat Storage 2.1) - Will not fix
GHSA
GHSA-94vh-mfcc-fg39: Insecure temporary file vulnerability in RedHat vsdm 4
ghsa_unreviewed·2022-05-05
CVE-2013-4280 [MEDIUM] CWE-668 GHSA-94vh-mfcc-fg39: Insecure temporary file vulnerability in RedHat vsdm 4
Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/security/cve/cve-2013-4280https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4280https://security-tracker.debian.org/tracker/CVE-2013-4280https://access.redhat.com/security/cve/cve-2013-4280https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4280https://security-tracker.debian.org/tracker/CVE-2013-4280
2019-11-04
Published