Back

MEDIUM

oprofile: do_dump_data function symlink attack via opd_pipe

Published Jun 9, 2011

Description

The do_dump_data function in utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to create or overwrite arbitrary files via a crafted --session-dir argument in conjunction with a symlink attack on the opd_pipe file, a different vulnerability than CVE-2011-1760.

Affected products

Remediation

Red Hat statement

Red Hat currently does not plan to address this issue. For details refer to: https://bugzilla.redhat.com/show_bug.cgi?id=700883#c18

Metrics

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 9, 2011
Updated Aug 6, 2024
Reserved Jun 9, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Apr 26, 2011