CVE-2011-2684

Source
https://nvd.nist.gov/vuln/detail/CVE-2011-2684
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2011-2684.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2011-2684
Published
2017-10-23T18:29:00Z
Modified
2024-11-21T01:28:45Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

foo2zjs before 20110722dfsg-3ubuntu1 as packaged in Ubuntu, 20110722dfsg-1 as packaged in Debian unstable, and 20090908dfsg-5.1+squeeze0 as packaged in Debian squeeze create temporary files insecurely, which allows local users to write over arbitrary files via a symlink attack on /tmp/foo2zjs.

References

Affected packages

Debian:11 / foo2zjs

Package

Name
foo2zjs
Purl
pkg:deb/debian/foo2zjs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20110722dfsg-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / foo2zjs

Package

Name
foo2zjs
Purl
pkg:deb/debian/foo2zjs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20110722dfsg-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / foo2zjs

Package

Name
foo2zjs
Purl
pkg:deb/debian/foo2zjs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20110722dfsg-1

Ecosystem specific

{
    "urgency": "low"
}