MEDIUM
zsh insecure /tmp file usage
Published Dec 4, 2007
4.6
MEDIUMCVSS 2.0
EPSS 0.33%
Description
Util/difflog.pl in zsh 4.3.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Affected products
No data.
AND
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. These issues did not affect the versions of the zsh package as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
References (12)
- http://osvdb.org/42481 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/27899 third-party-advisoryx_refsource_SECUNIA
- http://www.securityfocus.com/bid/26674 vdb-entryx_refsource_BID
- http://www.zsh.org/mla/workers/2007/msg01060.html mailing-listx_refsource_MLIST
- http://www.zsh.org/mla/workers/2007/msg01065.html mailing-listx_refsource_MLIST
- http://www.zsh.org/mla/workers/2007/msg01066.html mailing-listx_refsource_MLIST
- https://access.redhat.com/security/cve/CVE-2007-6209 Vendor Advisory
- https://bugs.gentoo.org/show_bug.cgi?id=201022 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=409871 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38812 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2007-6209
- https://www.cve.org/CVERecord?id=CVE-2007-6209
| Link | Providers | Tags |
|---|---|---|
| http://osvdb.org/42481 | vdb-entryx_refsource_OSVDB | |
| http://secunia.com/advisories/27899 | third-party-advisoryx_refsource_SECUNIA | |
| http://www.securityfocus.com/bid/26674 | vdb-entryx_refsource_BID | |
| http://www.zsh.org/mla/workers/2007/msg01060.html | mailing-listx_refsource_MLIST | |
| http://www.zsh.org/mla/workers/2007/msg01065.html | mailing-listx_refsource_MLIST | |
| http://www.zsh.org/mla/workers/2007/msg01066.html | mailing-listx_refsource_MLIST | |
| https://access.redhat.com/security/cve/CVE-2007-6209 | Vendor Advisory | |
| https://bugs.gentoo.org/show_bug.cgi?id=201022 | x_refsource_MISC | |
| https://bugzilla.redhat.com/show_bug.cgi?id=409871 | Issue Tracking | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/38812 | vdb-entryx_refsource_XF | |
| https://nvd.nist.gov/vuln/detail/CVE-2007-6209 | ||
| https://www.cve.org/CVERecord?id=CVE-2007-6209 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 4, 2007
Updated Aug 7, 2024
Reserved Dec 3, 2007
Link CVE-2007-6209
CISA Vulnrichment
Updated n/a