1.9
CVSSv2

CVE-2008-4579

Published: 15/10/2008 Updated: 13/02/2023
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The (1) fence_apc and (2) fence_apc_snmp programs, as used in (a) fence 2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows local users to append to arbitrary files via a symlink attack on the apclog temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

gentoo cman 2.02.00

gentoo fence 2.02.00

Vendor Advisories

Debian Bug report logs - #496410 The possibility of attack with the help of symlinks in some Debian packages Package: cman; Maintainer for cman is Debian HA Maintainers <debian-ha-maintainers@listsaliothdebianorg>; Source for cman is src:redhat-cluster (PTS, buildd, popcon) Reported by: "Dmitry E Oboukhov" <dimka@uvw ...
Multiple insecure temporary file handling vulnerabilities were discovered in Red Hat Cluster A local attacker could exploit these to overwrite arbitrary local files via symlinks (CVE-2008-4192, CVE-2008-4579, CVE-2008-4580, CVE-2008-6552) ...