CVE-2011-2765

Description

pyro before 3.15 unsafely handles pid files in temporary directory locations and opening the pid file as root. An attacker can use this flaw to overwrite arbitrary files via symlinks.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.433

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2011-2765 are fixed in Python-pyro 3.15Windows
Vulnerabilities CVE-2011-2765 are fixed in Python-pyro for linux 3.15Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234