Security Advisory

CVE-2019-12779

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-06-07 19:44:25
Last updated 2024-08-04 23:32:54
Assigner mitre
State PUBLISHED

Description

libqb before 1.0.5 allows local users to overwrite arbitrary files via a symlink attack, because it uses predictable filenames (under /dev/shm and /tmp) without O_EXCL.