CVE-2011-2765

Source
https://nvd.nist.gov/vuln/detail/CVE-2011-2765
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2011-2765.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2011-2765
Aliases
Withdrawn
2024-06-30T13:40:11.990745Z
Published
2018-08-20T13:29:00Z
Modified
2024-04-11T07:40:48Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.

References

Affected packages

Debian:10 / pyro

Package

Name
pyro
Purl
pkg:deb/debian/pyro?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:3.14-1

Ecosystem specific

{
    "urgency": "low"
}