Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating the LOCKPATH directory, then modifying it after the symbolic link check occurs. NOTE: this is due to an incomplete fix for CVE-2008-1569.
References
Configurations
Information
Published : 2008-03-31 15:44
Updated : 2017-08-07 18:30
NVD link : CVE-2008-1570
Mitre link : CVE-2008-1570
JSON object : View
CWE
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Products Affected
policyd-weight
- policyd-weight