CVE-2013-7171: Input Validation
Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitrary code with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-7171?
The severity of CVE-2013-7171 is critical with a severity value of 9.8.
What is the impact of CVE-2013-7171?
CVE-2013-7171 allows remote attackers to execute arbitrary code with root privileges on Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2.
How can I fix CVE-2013-7171?
To fix CVE-2013-7171, ensure that the /tmp directory on Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2 has proper permissions and is not world-writable.
Where can I find more information about CVE-2013-7171?
More informatioon about CVE-2013-7171 can be found at the following references: [1] https://security-tracker.debian.org/tracker/CVE-2013-7171, [2] http://www.openwall.com/lists/oss-security/2013/12/20/1, [3] https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-7171
What is the Common Weakness Enumeration (CWE) of CVE-2013-7171?
The CWE of CVE-2013-7171 is CWE-20.