apmscript in Apmd in Red Hat 7.2 "Enigma" allows local users to create or change the modification dates of arbitrary files via a symlink attack on the LOW_POWER temporary file, which could be used to cause a denial of service, e.g. by creating /etc/nologin and disabling logins.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/8268 | vdb entry |
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=56389 | vendor advisory |
http://marc.info/?l=bugtraq&m=100743394701962&w=2 | mailing list |
http://www.osvdb.org/5493 | vdb entry |