7.2
CVSSv2

CVE-2008-4474

Published: 07/10/2008 Updated: 06/02/2009
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

freeradius-dialupadmin in freeradius 2.0.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files in (1) backup_radacct, (2) clean_radacct, (3) monthly_tot_stats, (4) tot_stats, and (5) truncate_radacct.

Vulnerable Product Search on Vulmon Subscribe to Product

freeradius freeradius 2.0.4

Vendor Advisories

Debian Bug report logs - #496389 The possibility of attack with the help of symlinks in some Debian packages Package: freeradius-dialupadmin; Maintainer for freeradius-dialupadmin is (unknown); Reported by: "Dmitry E Oboukhov" <dimka@uvwru> Date: Sun, 24 Aug 2008 18:10:19 UTC Severity: grave Tags: security Fixed in vers ...