CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,525 vulnerabilities with CWE-59
CVE-2014-3563
SaltStack Salt < 2014.1.10 - Local Privilege Escalation via Temporary File Handling
CVE-2014-2524
GNU Readline <6.3-3 - Local File Manipulation
CVE-2014-5260
xml-dt < 0.64 - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2014-5045
Linux Kernel < 3.15.8 - Denial of Service via Symlink Handling in mountpoint_last
CVE-2014-5030
Canonical Ubuntu Linux < 1.7.4 - Symlink Following
CVE-2014-5029
CUPS 1.7.4 - Arbitrary File Read via Symlink Attack in Web Interface
CVE-2014-3537
CUPS < 1.7.4 - Arbitrary File Read via Symlink Attack in RSS Cache
CVE-2014-3486
Red Hat CloudForms Management Engine < 5.2.4.2 - Local Arbitrary Command Execution via Symlink Attack
CVE-2014-4038
ppc64-diag 2.6.1 - Local Info Disclosure
CVE-2014-3977
IBM AIX 6.1/7.1 & VIOS 2.2.x - Local Privilege Escalation
CVE-2014-3986
Lynis <1.5.5 - Local File Overwrite
CVE-2014-3982
Lynis <1.5.5 - Local File Overwrite
CVE-2014-3981
PHP < 5.3.29 - Arbitrary File Overwrite via Symlink Attack on /tmp/phpglibccheck
CVE-2014-1934
eyeD3 <7.0.3, 0.6.18 - Local File Modification
CVE-2014-3424
Mageia < 24.3 - Symlink Following
CVE-2014-3423
Mageia < 24.3 - Symlink Following
CVE-2014-3422
GNU Emacs < 24.3 - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2014-3421
Mageia < 24.3 - Symlink Following
CVE-2014-2893
Opensuse < 3.5 - Symlink Following
CVE-2014-1932
Pillow < 2.3.1 - Arbitrary File Write via Symlink Attack on Temporary Files
CVE-2014-1272
Apple iOS < 7.1 and tvOS < 6.1 - Arbitrary File Permission Change via Symlink in CrashHouseKeeping
CVE-2014-1838
logilab-commons <0.61.0 - Local Privilege Escalation
CVE-2014-1876
OpenJDK/Oracle Java - Local Privilege Escalation
CVE-2014-1640
Axiom <20100701-1.1 - Local File Overwrite
CVE-2014-1639
syncevo/installcheck-local.sh <1.3.99.7 - Local File Overwrite
Details
Vulnerabilities 1,525
Exploit Likelihood Medium