A vulnerability has been discovered in SnortCenter v0.9.5. It has been reported that SnortCenter creates temporary files using predictable file names. By anticipating the name of a temporary file a local attacker may be able to corrupt sensitive data by creating a symbolic link to a SnortCenter writable system resource. It is not yet known whether versions prior to v0.9.5 are affected by this issue.
A vulnerability has been discovered in SnortCenter v0.9.5. It has been reported that SnortCenter creates temporary files using predictable file names. By anticipating the name of a temporary file a local attacker may be able to corrupt sensitive data by creating a symbolic link to a SnortCenter writable system resource. It is not yet known whether versions prior to v0.9.5 are affected by this issue.