CVE-2014-3982
08.06.2014, 18:55
include/tests_webservers in Lynis before 1.5.5 on AIX allows local users to overwrite arbitrary files via a symlink attack on a /tmp/lynis.##### file.
| Vendor | Product | Version |
|---|---|---|
| cisofy | lynis | 𝑥 ≤ 1.5.4 |
| cisofy | lynis | 1.5.0 |
| cisofy | lynis | 1.5.1 |
| cisofy | lynis | 1.5.2 |
| cisofy | lynis | 1.5.3 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References