CVE-2014-2524
The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink attack on a /var/tmp/rltrace.[PID] file.
Ver en NVDSeveridad
N/A
EPSS
Probabilidad de explotación (próx. 30 días): 0.0014 (0.1%)
Percentil: 33.9%
EPSS: 2026-05-06
Afecta
mageia:mageiagnu:readlineopensuse:opensusefedoraproject:fedoraDescripción técnica
The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink attack on a /var/tmp/rltrace.[PID] file.
Publicada: 20/8/2014, 14:55:05
Última modificación: 6/5/2026, 22:30:45
Referencias
- http://advisories.mageia.org/MGASA-2014-0319.html
- http://lists.gnu.org/archive/html/bug-readline/2014-03/msg00057.html
- http://lists.opensuse.org/opensuse-security-announce/2014-09/msg00037.html
- http://seclists.org/oss-sec/2014/q1/579
- http://seclists.org/oss-sec/2014/q1/587
- http://www.mandriva.com/security/advisories?name=MDVSA-2014:154
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:132
- https://bugzilla.redhat.com/show_bug.cgi?id=1077023