openvas-scanner before 2011-09-11 creates a temporary...
High severity
Unreviewed
Published
Apr 22, 2022
to the GitHub Advisory Database
•
Updated Apr 3, 2024
Description
Published by the National Vulnerability Database
Nov 25, 2019
Published to the GitHub Advisory Database
Apr 22, 2022
Last updated
Apr 3, 2024
openvas-scanner before 2011-09-11 creates a temporary file insecurely when generating OVAL system characteristics document with the ovaldi integrated tool enabled. A local attacker could use this flaw to conduct symlink attacks to overwrite arbitrary files on the system.
References