7.2
CVSSv2

CVE-2008-4580

Published: 15/10/2008 Updated: 13/02/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

fence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fence_manual.fifo temporary file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gentoo cman 2.02.00

gentoo fence 2.02.00

Vendor Advisories

Debian Bug report logs - #496410 The possibility of attack with the help of symlinks in some Debian packages Package: cman; Maintainer for cman is Debian HA Maintainers <debian-ha-maintainers@listsaliothdebianorg>; Source for cman is src:redhat-cluster (PTS, buildd, popcon) Reported by: "Dmitry E Oboukhov" <dimka@uvw ...
Multiple insecure temporary file handling vulnerabilities were discovered in Red Hat Cluster A local attacker could exploit these to overwrite arbitrary local files via symlinks (CVE-2008-4192, CVE-2008-4579, CVE-2008-4580, CVE-2008-6552) ...