as31 2.3.1-4 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or truncate files via a symlink attack.
CVSS Details
- CVSS 3.1 Base Score: 4.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade as31 | Jul 30, 2024 | Mar 19, 2012 |
| Gentoo Linux | — | Upgrade net-analyzer/lft.Upgrade www-apps/egroupware.Upgrade dev-php/suhosin.Upgrade sys-cluster/ganglia.Upgrade x11-libs/vte.Upgrade x11-misc/slock.Upgrade net-im/gg-transport. | Oct 30, 2017 | Mar 19, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub