7.2
CVSSv2

CVE-2008-4108

Published: 18/09/2008 Updated: 08/08/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files via a symlink attack on a tmp$RANDOM.tmp temporary file. NOTE: there may not be common usage scenarios in which tmp$RANDOM.tmp is located in an untrusted directory.

Vulnerable Product Search on Vulmon Subscribe to Product

python software foundation python 2.4.5

Vendor Advisories

Debian Bug report logs - #498899 Unsecure use of temporary files Package: python24-examples; Maintainer for python24-examples is (unknown); Reported by: Jan Hauke Rahm <jhr@debianorg> Date: Sun, 14 Sep 2008 11:12:01 UTC Severity: normal Tags: patch, pending, security Done: Matthias Klose <doko@debianorg> Bug i ...