VYPR
Unrated severityNVD Advisory· Published Oct 1, 2012· Updated Apr 29, 2026

CVE-2012-3500

CVE-2012-3500

Description

scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2) standard error output file.

Affected products

2
  • cpe:2.3:a:devscripts_devel_team:devscripts:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:devscripts_devel_team:devscripts:*:*:*:*:*:*:*:*range: <=2.12.1
    • cpe:2.3:a:devscripts_devel_team:devscripts:2.12.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

14

News mentions

0

No linked articles in our index yet.