CVE-2009-4193

Merkaartor 0.14 allows local users to append data to arbitrary files via a symlink attack on the /tmp/merkaartor.log temporary file.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.3 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:N/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
VendorProductVersion
merkaartormerkaartor
0.14
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
merkaartor
bullseye
0.18.4+ds-5
fixed
lenny
not-affected
bookworm
0.19.0+ds-3
fixed
sid
0.20.0+ds-1
fixed
trixie
0.20.0+ds-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
merkaartor
xenial
not-affected
wily
ignored
vivid
ignored
utopic
ignored
trusty
dne
saucy
ignored
raring
ignored
quantal
ignored
precise
not-affected
oneiric
ignored
natty
ignored
maverick
ignored
lucid
not-affected
karmic
ignored
jaunty
ignored
intrepid
ignored
hardy
dne
dapper
dne