CVE-2009-1893

The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file, related to the "dhcpd -t" command.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 24%
VendorProductVersion
redhatenterprise_linux
3.0
redhatenterprise_linux
3.0
redhatenterprise_linux
3.0
redhatenterprise_linux
3.0
iscdhcp
3.0.1:rc1
iscdhcp
3.0.1:rc10
iscdhcp
3.0.1:rc11
iscdhcp
3.0.1:rc12
iscdhcp
3.0.1:rc13
iscdhcp
3.0.1:rc14
iscdhcp
3.0.1:rc2
iscdhcp
3.0.1:rc5
iscdhcp
3.0.1:rc6
iscdhcp
3.0.1:rc7
iscdhcp
3.0.1:rc8
iscdhcp
3.0.1:rc9
𝑥
= Vulnerable software versions