VULNERABILITY INTELLIGENCE

CVE-2009-4193

CVSS score3.3 LOW
EPSS probability0.32%
CISA KEVNot currently listed
Published2009-12-03
Last modified2026-06-16
CVSS vectorAV:L/AC:M/Au:N/C:N/I:P/A:P

Description

Merkaartor 0.14 allows local users to append data to arbitrary files via a symlink attack on the /tmp/merkaartor.log temporary file.

Weakness classification

  • CWE-59: Improper Link Resolution Before File Access ('Link Following')

Primary references