CVE-2013-1976
Last modified
CVE-2013-1976 is a vulnerability of currently unknown severity. The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0, and Red Hat Enterprise Linux 5 and 6, allow local users to change the ownership of arbitrary files via a symlink attack on (a) tomcat5-initd.log, (b) tomcat6-initd.log, (c) catalina.out, or (d) tomcat7-initd.log.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
The (1) tomcat5, (2) tomcat6, and (3) tomcat7 init scripts, as used in the RPM distribution of Tomcat for JBoss Enterprise Web Server 1.0.2 and 2.0.0, and Red Hat Enterprise Linux 5 and 6, allow local users to change the ownership of arbitrary files via a symlink attack on (a) tomcat5-initd.log, (b) tomcat6-initd.log, (c) catalina.out, or (d) tomcat7-initd.log.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Jboss Enterprise Web Server | 1.0.2 |
| Redhat | Jboss Enterprise Web Server | 2.0.0 |
| Redhat | Enterprise Linux | 5 |
| Redhat | Enterprise Linux | 6.0 |
References
- http://rhn.redhat.com/errata/RHSA-2013-0869.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0870.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0871.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0872.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=927622Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0869.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0870.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0871.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0872.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=927622Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-1976?
How severe is CVE-2013-1976?
How do I fix CVE-2013-1976?
Are you affected by CVE-2013-1976?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
