MEDIUM · 6.9

CVE-2009-0416

The SSL certificate setup program (genSslCert.sh) in Standards Based Linux Instrumentation for Manageability (SBLIM) sblim-sfcb 1.3.2 allows local users to overwrite arbitrary files via a symlink atta...

Vulnerability Description

The SSL certificate setup program (genSslCert.sh) in Standards Based Linux Instrumentation for Manageability (SBLIM) sblim-sfcb 1.3.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /var/tmp/key.pem, (2) /var/tmp/cert.pem, and (3) /var/tmp/ssl.cnf temporary files.

CVSS Score

6.9

MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
Standards Based Linux InstrumentationSblim-Sfcb1.3.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-0416?

CVE-2009-0416 is a vulnerability with a CVSS score of 6.9 (MEDIUM). The SSL certificate setup program (genSslCert.sh) in Standards Based Linux Instrumentation for Manageability (SBLIM) sblim-sfcb 1.3.2 allows local users to overwrite arbitrary files via a symlink atta...

How severe is CVE-2009-0416?

CVE-2009-0416 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-0416?

Check the references section above for vendor advisories and patch information. Affected products include: Standards Based Linux Instrumentation Sblim-Sfcb.