scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2) standard error output file.
2012-10-01T00:55:01.460
2025-04-11T00:51:21.963
Deferred
CVSSv2: 1.2 (LOW)
AV:L/AC:H/Au:N/C:N/I:P/A:N
1.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | devscripts_devel_team | devscripts | ≤ 2.12.1 | Yes |
Application | devscripts_devel_team | devscripts | 2.12.0 | Yes |
Application | fedora | rpmdevtools | ≤ 8.2-1 | No |