1.9
CVSSv2

CVE-2008-4579

Published: 15/10/2008 Updated: 13/02/2023
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The (1) fence_apc and (2) fence_apc_snmp programs, as used in (a) fence 2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows local users to append to arbitrary files via a symlink attack on the apclog temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

gentoo cman 2.02.00

gentoo fence 2.02.00

Vendor Advisories

Multiple insecure temporary file handling vulnerabilities were discovered in Red Hat Cluster A local attacker could exploit these to overwrite arbitrary local files via symlinks (CVE-2008-4192, CVE-2008-4579, CVE-2008-4580, CVE-2008-6552) ...
Debian Bug report logs - #496410 The possibility of attack with the help of symlinks in some Debian packages Package: cman; Maintainer for cman is Debian HA Maintainers <debian-ha-maintainers@listsaliothdebianorg>; Source for cman is src:redhat-cluster (PTS, buildd, popcon) Reported by: "Dmitry E Oboukhov" <dimka@uvw ...