CVE-2009-4193

EUVD-2009-4163
Merkaartor 0.14 allows local users to append data to arbitrary files via a symlink attack on the /tmp/merkaartor.log temporary file.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:N/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
Affected Products (NVD)
VendorProductVersion
merkaartormerkaartor
0.14
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
merkaartor
bookworm
0.19.0+ds-3
fixed
bullseye
0.18.4+ds-5
fixed
lenny
not-affected
sid
0.20.0+ds-1
fixed
trixie
0.20.0+ds-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
merkaartor
dapper
dne
hardy
dne
intrepid
ignored
jaunty
ignored
karmic
ignored
lucid
not-affected
maverick
ignored
natty
ignored
oneiric
ignored
precise
not-affected
quantal
ignored
raring
ignored
saucy
ignored
trusty
dne
utopic
ignored
vivid
ignored
wily
ignored
xenial
not-affected