CVE-2012-3500

Severity CVSS v4.0:
Pending analysis
Type:
CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Publication date:
01/10/2012
Last modified:
11/04/2025

Description

scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2) standard error output file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:devscripts_devel_team:devscripts:*:*:*:*:*:*:*:* 2.12.1 (including)
cpe:2.3:a:devscripts_devel_team:devscripts:2.12.0:*:*:*:*:*:*:*
cpe:2.3:a:fedora:rpmdevtools:*:*:*:*:*:*:*:* 8.2-1 (including)


References to Advisories, Solutions, and Tools