CVE-2006-3118
spread uses a temporary file with a static filename based on the port number, which allows local users to cause a denial of service by creating the file during a race condition between unlink and bind function calls.
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
spread uses a temporary file with a static filename based on the port number, which allows local users to cause a denial of service by creating the file during a race condition between unlink and bind function calls. NOTE: spread deletes this temporary file before use, which could cause conflicts with other programs that use the same filename, but this is not a distinct issue.
- CVSS 2.0
- 1.2 LOWAV:L/AC:H/Au:N/C:N/I:N/A:P
- EPSS
- 0.30% probability · 23th percentile
- CISA KEV
- Not listed
- Affected
- canonical/spread
- Source
- security@debian.org
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=375617
- http://www.securityfocus.com/bid/18675
- https://launchpad.net/distros/ubuntu/+source/spread/+bug/44171
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=375617
- http://www.securityfocus.com/bid/18675
- https://launchpad.net/distros/ubuntu/+source/spread/+bug/44171
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.