CVE-2012-3440: Red Hat Enterprise Linux
Medium severity, CVSS 5.6. EPSS: 0.4% chance of exploitation in the next 30 days.
A certain Red Hat script for sudo 1.7.2 on Red Hat Enterprise Linux (RHEL) 5 allows local users to overwrite arbitrary files via a symlink attack on the /var/tmp/nsswitch.conf.bak temporary file.
Affected products
- Red Hat Enterprise Linux: version 5 only
- Todd Miller Sudo: version 1.7.2 only
Published 2012-08-08. Last modified 2026-06-16.