← Vulnerability feed

Vulnerability record · CVE-2013-7171 · published 21 November 2019

CVE-2013-7171: Slackware linux improper input validation vulnerability

Slackware · Slackware Linux

Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitrary code with root privileges.

9.8 CVSS 3.1 Critical EPSS 6.3% · top 6.6% CWE-20 · Improper input validation
9.8CVSS 3.1 base score, v2 10.0
6.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitrary code with root privileges.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-7171 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-6235Gnu privacy guard vulnerabilityA "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary c…EPSS 5.9%10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2004-0891Rob flynn gaim vulnerabilityBuffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possi…EPSS 6.9%10.0CVE-2004-0226Midnight commander vulnerabilityMultiple buffer overflows in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.EPSS 3.9%10.0CVE-2000-0844Caldera openlinux ebuilder permissions and access controls vulnerabilitySome functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to exec…EPSS 16%10.0CVE-1999-0368Proftpd project proftpd vulnerabilityBuffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.EPSS 40%10.0CVE-1999-0192Redhat linux vulnerabilityBuffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.EPSS 10%10.0CVE-1999-1299Redhat linux vulnerabilityrcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 i…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2013-7171), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.