CVE-2011-2765

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
20/08/2018
Last modified:
21/11/2024

Description

pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pyro_project:pyro:*:*:*:*:*:*:*:* 3.15 (excluding)