CVE-2012-3440: Red Hat Enterprise Linux

Medium severity, CVSS 5.6. EPSS: 0.4% chance of exploitation in the next 30 days.

A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file.

Affected products

Published 2012-08-08. Last modified 2026-06-16.