CVE-2014-4038
EPSS 0.05%
Description
ppc64-diag 2.6.1 allows local users to overwrite arbitrary files via a symlink attack related to (1) rtas_errd/diag_support.c and /tmp/get_dt_files, (2) scripts/ppc64_diag_mkrsrc and /tmp/diagSEsnap/snapH.tar.gz, or (3) lpd/test/lpd_ela_test.sh and /var/tmp/ras.
How to fix CVE-2014-4038
To remediate CVE-2014-4038, upgrade the affected package to a fixed version below.
- Debian/ppc64-diag—upgrade to 2.7.1-5 or later
Is CVE-2014-4038 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.7.1-5