The (1) fence_apc and (2) fence_apc_snmp programs, as used in (a) fence 2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows local users to append to arbitrary files via a symlink attack on the apclog temporary file.
CVSS Details
- CVSS 3.1 Base Score: 3.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade cman-develUpgrade cman | Dec 1, 2016 | Oct 15, 2008 |
| Gentoo Linux | — | Upgrade sys-cluster/fence. | Oct 30, 2017 | Oct 15, 2008 |
| Oracle_linux | — | Upgrade cman-develUpgrade cman | Oct 16, 2024 | Oct 15, 2008 |
| Ubuntu | — | Upgrade rgmanagerUpgrade cmanUpgrade ccsUpgrade gfs2-toolsUpgrade fenceUpgrade libcman1 | Nov 8, 2024 | Oct 15, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub