CVE-2019-12779

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
07/06/2019
Last modified:
03/07/2021

Description

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:clusterlabs:libqb:*:*:*:*:*:*:*:* 1.0.5 (excluding)