CVE-2014-3982

Lynis <1.5.5 - Local File Overwrite

Title source: llm
STIX 2.1

Description

include/tests_webservers in Lynis before 1.5.5 on AIX allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.##### file.

References (4)

Core 4
Core References
Patch x_refsource_confirm
http://cisofy.com/files/lynis-1.5.5.tar.gz
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2014/06/07/3
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2014/06/05/14
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2014/06/06/12

Scores

EPSS 0.0034
EPSS Percentile 25.7%

Details

CWE
CWE-59
Status published
Products (5)
cisofy/lynis 1.5.0
cisofy/lynis 1.5.1
cisofy/lynis 1.5.2
cisofy/lynis 1.5.3
cisofy/lynis < 1.5.4
Published Jun 08, 2014
Tracked Since Feb 18, 2026