CVE-2013-4392
published 2013-10-28CVE-2013-4392: systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on…
PriorityP421medium5CVSS 3.1
AVLACLPRLUIRSUCHINAN
EPSS
0.47%
38.8th percentile
systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | systemd | — | — |
| systemd_project | systemd | < 239 | 239 |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r4xg-5wrj-c7g3: systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink
ghsa_unreviewed·2022-05-13
CVE-2013-4392 [LOW] CWE-59 GHSA-r4xg-5wrj-c7g3: systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink
systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.
OSV
CVE-2013-4392: systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink
osv·2013-10-28·CVSS 5.0
CVE-2013-4392 [MEDIUM] CVE-2013-4392: systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink
systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.
Red Hat
systemd: TOCTOU race condition when updating file permissions and SELinux security contexts
vendor_redhat·2013-09-23·CVSS 5.0
CVE-2013-4392 [MEDIUM] CWE-367 systemd: TOCTOU race condition when updating file permissions and SELinux security contexts
systemd: TOCTOU race condition when updating file permissions and SELinux security contexts
systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.
Package: systemd (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2013-4392: systemd - systemd, when updating file permissions, allows local users to change the permis...
vendor_debian·2013·CVSS 5.0
CVE-2013-4392 [MEDIUM] CVE-2013-4392: systemd - systemd, when updating file permissions, allows local users to change the permis...
systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357http://www.openwall.com/lists/oss-security/2013/10/01/9https://bugzilla.redhat.com/show_bug.cgi?id=859060http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=725357http://www.openwall.com/lists/oss-security/2013/10/01/9https://bugzilla.redhat.com/show_bug.cgi?id=859060
2013-10-28
Published