openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi integrated tool enabled. A local attacker could use this flaw to conduct symlink attacks to overwrite arbitrary files on the system.
2019-11-25T22:15:11.013
2024-11-21T01:30:19.103
Modified
CVSSv3.1: 7.1 (HIGH)
AV:L/AC:L/Au:N/C:N/I:C/A:C
3.9
9.2
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openvas | openvas-scanner | < 2011-09-11 | Yes |