Security Advisory

CVE-2008-1570

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-03-31 22:00:00
Last updated 2024-08-07 08:24:42
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating the LOCKPATH directory, then modifying it after the symbolic link check occurs. NOTE: this is due to an incomplete fix for CVE-2008-1569.