fedup 0.9.0 in Fedora 19, 20, and 21 uses a temporary directory with a static name for its download cache, which allows local users to cause a denial of service (prevention of system updates).
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:59
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.fedoraproject.org/pipermail/package-announce/2014-November/141698.html - Vendor Advisory | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2014-November/142698.html - Vendor Advisory | |
References | () http://lists.fedoraproject.org/pipermail/package-announce/2014-November/142933.html - | |
References | () http://www.securityfocus.com/bid/70874 - | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=1066679 - Vendor Advisory | |
References | () https://github.com/wgwoods/fedup/issues/44 - Patch, Vendor Advisory |
Information
Published : 2014-12-02 01:59
Updated : 2024-11-21 01:59
NVD link : CVE-2013-6494
Mitre link : CVE-2013-6494
CVE.ORG link : CVE-2013-6494
JSON object : View
Products Affected
fedup_project
- fedup
fedoraproject
- fedora
CWE
CWE-17
DEPRECATED: Code