CVE-2013-0261

high
Published 2013-03-08 · Modified 2026-04-30
CVSS v3
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v2
4.4
VIR risk
8.8

Description

A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This vulnerability allows the local user to overwrite arbitrary files on the system, potentially leading to system compromise or data corruption.

Predictions

Exploit likelihood
82%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2013-0595.html

Application impact

VendorProductVersionsFixed
openstackessex-
openstackfolsom-

References

CWEs

CWE-59 CWE-264

Verify integrity in audit chain (admin only). AS-IS.