Back

HIGH

katello-debug: Possible symlink attacks due to use of predictable file names

Published Jul 27, 2018

Description

A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 27, 2018
Updated Aug 6, 2024
Reserved Nov 23, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 21, 2016