The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augnew file.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 1 | augeas | 2013-12-02 20:28 | ALAS-2013-250 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv2 | 3.3 | AV:L/AC:M/Au:N/C:P/I:P/A:N |
NVD | CVSSv2 | 3.3 | AV:L/AC:M/Au:N/C:P/I:P/A:N |