7.2
CVSSv2

CVE-2008-4580

Published: 15/10/2008 Updated: 13/02/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

fence_manual, as used in fence 2.02.00-r1 and possibly cman, allows local users to modify arbitrary files via a symlink attack on the fence_manual.fifo temporary file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gentoo cman 2.02.00

gentoo fence 2.02.00

Vendor Advisories

Multiple insecure temporary file handling vulnerabilities were discovered in Red Hat Cluster A local attacker could exploit these to overwrite arbitrary local files via symlinks (CVE-2008-4192, CVE-2008-4579, CVE-2008-4580, CVE-2008-6552) ...
Debian Bug report logs - #496410 The possibility of attack with the help of symlinks in some Debian packages Package: cman; Maintainer for cman is Debian HA Maintainers <debian-ha-maintainers@listsaliothdebianorg>; Source for cman is src:redhat-cluster (PTS, buildd, popcon) Reported by: "Dmitry E Oboukhov" <dimka@uvw ...