CVE-2011-2684

Source
https://cve.org/CVERecord?id=CVE-2011-2684
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2011-2684.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2011-2684
Downstream
Published
2017-10-23T18:29:00Z
Modified
2026-04-10T03:41:51.811997Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

foo2zjs before 20110722dfsg-3ubuntu1 as packaged in Ubuntu, 20110722dfsg-1 as packaged in Debian unstable, and 20090908dfsg-5.1+squeeze0 as packaged in Debian squeeze create temporary files insecurely, which allows local users to write over arbitrary files via a symlink attack on /tmp/foo2zjs.

References

Affected packages