CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,525 vulnerabilities with CWE-59
CVE-2013-4214
Nagios Core < 3.5.1 - Arbitrary File Write via Symlink Attack on RSS Newsfeed Cache
CVE-2013-2029
Red Hat OpenStack - Arbitrary File Overwrite via Symlink Attack on Temporary Nagios Configuration File
CVE-2013-4392 MEDIUM
systemd < 239 - Symlink Attack via File Permission Update
CVSS 5.0
CVE-2013-4157
Red Hat Storage 2.0 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
CVE-2013-1444
txt2man 1.5.5-2 1.5.5-4 - Arbitrary File Overwrite via Symlink Attack
CVE-2013-4136
Phusion Passenger < 4.0.6 - Privilege Escalation via Symlink Attack on Predictable /tmp Directory
CVE-2013-2217
Suds 0.4 - Symlink Attack via Predictable Cache File in /tmp/suds/
CVE-2013-4169
GNOME Display Manager < 2.21.1 - Local Privilege Escalation via Symlink Attack on /tmp/.X11-unix/
CVE-2013-3368
Request Tracker <3.8.17, <4.0.13 - Local Privilege Escalation
CVE-2013-1888
pip < 1.3 - Arbitrary File Overwrite via Symlink Attack on Temporary Directory
CVE-2013-1976
JBoss Enterprise Web Server 1.0.2 and 2.0.0 - Symlink Attack via Tomcat Init Script Log Files
CVE-2013-0927
Google Chrome OS <26.0.1410.57 - Info Disclosure
CVE-2013-1495
Oracle Support Tools < 4.3.2 - Arbitrary File Modification via Symlink Attack
CVE-2013-1423
FusionForge 5.0-5.2 - Symlink and Hard Link Attack via Multiple Scripts
CVE-2013-0261 HIGH
OpenStack Essex - Arbitrary File Write via Symlink Attack on Predictable Temporary File
CVSS 8.8
CVE-2013-0200
HP Linux Imaging and Printing Project < 3.12.4 - Arbitrary File Write via Symlink Attack on Temporary Files
CVE-2012-1093 HIGH
Debian x11-common <7.6+12 - Privilege Escalation
CVSS 7.8
CVE-2012-6114 MEDIUM
git-extras 1.7.0 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
CVSS 5.5
CVE-2012-2945 HIGH
Hadoop 1.0.3 - Symlink Vulnerability
CVSS 7.5
CVE-2012-0871
systemd < 37 - Arbitrary File Write via Symlink Attack on X11 User Directory
CVE-2012-1088
iproute2 <3.3.0 - Local Privilege Escalation
CVE-2012-0786
augeas < 1.0.0 - Arbitrary File Overwrite via Symlink Attack on .augnew File
CVE-2012-5564
Android Debug Bridge <4.1.1 - Local Privilege Escalation
CVE-2012-6348
Centrify Deployment Manager 2.1.0.283 - Arbitrary File Write via Symlink Attack on Temporary Files
CVE-2012-3329
IBM Advanced Settings Utility & Bootable Media Creator - Arbitrary File Write via Symlink Attack
Details
Vulnerabilities 1,525
Exploit Likelihood Medium