Vulnerability Details CVE-2011-2684
foo2zjs before 20110722dfsg-3ubuntu1 as packaged in Ubuntu, 20110722dfsg-1 as packaged in Debian unstable, and 20090908dfsg-5.1+squeeze0 as packaged in Debian squeeze create temporary files insecurely, which allows local users to write over arbitrary files via a symlink attack on /tmp/foo2zjs.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 21.5%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 2.1
Products affected by CVE-2011-2684
-
cpe:2.3:a:rkkda:foo2zjs:20090908dfsg-5.1+squeeze0
-
cpe:2.3:a:rkkda:foo2zjs:20110722dfsg-1
-
cpe:2.3:a:rkkda:foo2zjs:20110722dfsg-3ubuntu1