The make include files in NetBSD before 1.6.2, as used in pmake 1.111 and other products, allow local users to overwrite arbitrary files via a symlink attack on a /tmp/_depend##### temporary file, related to (1) bsd.lib.mk and (2) bsd.prog.mk.
2011-05-23T22:55:01.410
2025-04-11T00:51:21.963
Deferred
CVSSv2: 3.3 (LOW)
AV:L/AC:M/Au:N/C:N/I:P/A:P
3.4
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | netbsd | netbsd | * | Yes |
Operating System | netbsd | netbsd | ≤ 1.6.1 | Yes |
Operating System | netbsd | netbsd | 1.0 | Yes |
Operating System | netbsd | netbsd | 1.1 | Yes |
Operating System | netbsd | netbsd | 1.2 | Yes |
Operating System | netbsd | netbsd | 1.2.1 | Yes |
Operating System | netbsd | netbsd | 1.3 | Yes |
Operating System | netbsd | netbsd | 1.3.1 | Yes |
Operating System | netbsd | netbsd | 1.3.2 | Yes |
Operating System | netbsd | netbsd | 1.3.3 | Yes |
Operating System | netbsd | netbsd | 1.4 | Yes |
Operating System | netbsd | netbsd | 1.4.1 | Yes |
Operating System | netbsd | netbsd | 1.4.2 | Yes |
Operating System | netbsd | netbsd | 1.4.3 | Yes |
Operating System | netbsd | netbsd | 1.5 | Yes |
Operating System | netbsd | netbsd | 1.5.1 | Yes |
Operating System | netbsd | netbsd | 1.5.2 | Yes |
Operating System | netbsd | netbsd | 1.5.3 | Yes |
Operating System | netbsd | netbsd | 1.6 | Yes |
Application | ihji | pmake | 1.111 | Yes |