3.6
CVSSv2

CVE-2008-0665

Published: 11/02/2008 Updated: 05/09/2008
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

wml_backend/p1_ipp/ipp.src in Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on the ipp.$$.tmp temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

website meta language website meta language 2.0.11

Vendor Advisories

Debian Bug report logs - #463907 Creates tempfiles in a unsafe way Package: wml; Maintainer for wml is Axel Beckert <abe@debianorg>; Source for wml is src:wml (PTS, buildd, popcon) Reported by: Frank Lichtenheld <djpig@debianorg> Date: Mon, 4 Feb 2008 04:54:01 UTC Severity: grave Tags: confirmed, patch, security ...