Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-4953

Опубликовано: 05 нояб. 2008
Источник: ubuntu
Приоритет: negligible
CVSS2: 6.9

Описание

firehol in firehol 1.256 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/.firehol-tmp-#####-- and (2) /tmp/firehol.conf temporary files. NOTE: the vendor disputes this vulnerability, stating that an attack "would require an attacker to create 1073741824*PID-RANGE symlinks.

РелизСтатусПримечание
dapper

ignored

end of life
devel

ignored

gutsy

ignored

end of life, was needed
hardy

ignored

intrepid

ignored

jaunty

ignored

karmic

ignored

upstream

ignored

Показывать по

Ссылки на источники

6.9 Medium

CVSS2

Связанные уязвимости

nvd
больше 17 лет назад

firehol in firehol 1.256 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/.firehol-tmp-#####-*-* and (2) /tmp/firehol.conf temporary files. NOTE: the vendor disputes this vulnerability, stating that an attack "would require an attacker to create 1073741824*PID-RANGE symlinks.

debian
больше 17 лет назад

firehol in firehol 1.256 allows local users to overwrite arbitrary fil ...

github
больше 3 лет назад

** DISPUTED ** firehol in firehol 1.256 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/.firehol-tmp-#####-*-* and (2) /tmp/firehol.conf temporary files. NOTE: the vendor disputes this vulnerability, stating that an attack "would require an attacker to create 1073741824*PID-RANGE symlinks."

6.9 Medium

CVSS2