Description
Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file, as demonstrated by a pathname different from the default /var/run/monkey.pid pathname.
References (3)
Core 3
Core References
Issue Tracking x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=688879
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/55905
Issue Tracking x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=672425
Scores
EPSS
0.0032
EPSS Percentile
23.4%
Details
CWE
CWE-59
Status
published
Products (1)
monkey-project/monkey
0.9.3
Published
Oct 05, 2012
Tracked Since
Feb 18, 2026