CVE-2012-5303 Information

Description

Monkey HTTP Daemon 0.9.3 might allow local users to overwrite arbitrary files via a symlink attack on a PID file as demonstrated by a pathname different from the default /var/run/monkey.pid pathname.

Reference

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=672425 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=688879 http://www.securityfocus.com/bid/55905

Share on: