CWE-59

Medium likelihood

Improper Link Resolution Before File Access ('Link Following')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

1,525 vulnerabilities with CWE-59
CVE-2012-5355
xdiagnose <2.5.2ubuntu0.1 - Local Privilege Escalation
CVE-2012-4455
openCryptoki 2.4.1 - Local Arbitrary File Write via Symlink Attack on Lock Files
CVE-2012-5303
Monkey HTTP Daemon <0.9.3 - Local File Overwrite
CVE-2012-2103
munin - Arbitrary File Write via Symlink Attack on Temporary Files
CVE-2012-4676
Tunnelblick <3.3beta20 - Local File Deletion
CVE-2012-3440
Red Hat Enterprise Linux 5 sudo Script - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2012-3345
ioquake3 < r2252 - Arbitrary File Write via Symlink Attack on /tmp/ioq3.pid
CVE-2012-2093
Gajim 0.15 - Arbitrary File Overwrite via Symlink Attack on Temporary Latex File
CVE-2012-0808
as31 <2.3.1-4 - Info Disclosure
CVE-2012-0054
golismero < 0.6.3 - Arbitrary File Overwrite via Symlink Attack on Admin/changes.dat
CVE-2011-4116 LOW
File::Temp - Improper Link Resolution Before File Access
CVSS 3.3
CVE-2011-3632 HIGH
hardlink < 0.1.2 - Symlink Attack via Improper Link Resolution
CVSS 7.1
CVE-2011-3351 HIGH
openvas-scanner < 2011-09-11 - Symlink Attack via Insecure Temporary File Creation
CVSS 7.1
CVE-2011-2924 MEDIUM
foomatic-filters < 4.0.12 - Symlink Attack via Insecure Temporary File Creation
CVSS 5.5
CVE-2011-2923 MEDIUM
foomatic-filters - Symlink Attack via Insecure Temporary File Creation
CVSS 5.5
CVE-2011-1136 MEDIUM
tesseract 2.03-2.04 - Arbitrary File Write via PID Link Guessing
CVSS 4.7
CVE-2011-3618 HIGH
atop - Symlink Attack via Insecure Tempfile Handling
CVSS 7.8
CVE-2011-5271 MEDIUM
Pacemaker < 1.1.6 - Insecure Temporary File Creation
CVSS 5.5
CVE-2011-1408 HIGH
ikiwiki < 3.20110608 - Symlink Attack via Tty Hijacking
CVSS 8.2
CVE-2011-2765 HIGH
Pyro < 3.15 - Arbitrary File Write via Symlink Attack on PID File
CVSS 7.5
CVE-2011-2684 MEDIUM
foo2zjs - Arbitrary File Write via Symlink Attack on /tmp/foo2zjs
CVSS 5.5
CVE-2011-3154
Update Manager Symlink Attack via Temporary File Handling
CVE-2011-0460
kbd < 1.14.1 - Arbitrary File Overwrite via Symlink Attack on /dev/shm/defkeymap.map
CVE-2011-3153
Canonical Ubuntu Linux < 1.1.0 - Symlink Following
CVE-2011-4363
Proc::ProcessTable <0.45 - Local Privilege Escalation
Details
Vulnerabilities 1,525
Exploit Likelihood Medium