← Back

CVE-2011-2473

nvd nist
Published: Jun 9, 2011Modified: Apr 29, 2026

JSON object

Loading...
6.3
Vector
AV:L/AC:M/Au:N/C:N/I:C/A:C
Exploitability: 3.4 / Impact: 9.2
Source: NVD

Description

The do_dump_data function in utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to create or overwrite arbitrary files via a crafted --session-dir argument in conjunction with a symlink attack on the opd_pipe file, a different vulnerability than CVE-2011-1760.

Affected (23)

Oprofile
Configuration A
23 vulnerable

References (14)

Timeline

No history available yet.