SB2012071204 - Race condition in Freedesktop systemd



SB2012071204 - Race condition in Freedesktop systemd

Published: July 12, 2012 Updated: August 11, 2020

Security Bulletin ID SB2012071204
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Race condition (CVE-ID: CVE-2012-1174)

The vulnerability allows a remote non-authenticated attacker to manipulate or delete data.

The rm_rf_children function in util.c in the systemd-logind login manager in systemd before 44, when logging out, allows local users to delete arbitrary files via a symlink attack on unspecified files, related to "particular records related with user session."


Remediation

Install update from vendor's website.