CVE-2013-4159
high
CVSS v3
—
CVSS v2
7.5
VIR risk
7.5
Description
ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp file vulnerabilities" in (1) tcp/tcp_connect.c, (2) server/eventscript.c, (3) tools/ctdb_diagnostics, (4) config/gdb_backtrace, and (5) include/ctdb_private.h.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://lists.opensuse.org/opensuse-updates/2014-06/msg00052.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| suse | 12.3 | affected | |
| suse | 13.1 | affected | |
References
- http://advisories.mageia.org/MGASA-2014-0274.html
- http://lists.opensuse.org/opensuse-updates/2014-06/msg00052.html
- http://wiki.samba.org/index.php/CTDB2releaseNotes#ctdb_2.5
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:177
- http://www.openwall.com/lists/oss-security/2014/05/29/12
- https://bugzilla.redhat.com/show_bug.cgi?id=986773
- https://git.samba.org/?p=ctdb.git%3Ba=commitdiff%3Bh=b9b9f6738fba5c32e87cb9c36b358355b444fb9b
- http://advisories.mageia.org/MGASA-2014-0274.html
- http://lists.opensuse.org/opensuse-updates/2014-06/msg00052.html
- http://wiki.samba.org/index.php/CTDB2releaseNotes#ctdb_2.5
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:177
- http://www.openwall.com/lists/oss-security/2014/05/29/12
- https://bugzilla.redhat.com/show_bug.cgi?id=986773
- https://git.samba.org/?p=ctdb.git%3Ba=commitdiff%3Bh=b9b9f6738fba5c32e87cb9c36b358355b444fb9b
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.