6.9
CVSSv2

CVE-2008-5157

Published: 18/11/2008 Updated: 08/08/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

tau 2.16.4 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/makefile.tau.*.##### or (2) /tmp/makefile.tau*.##### temporary file, related to the (a) tau_cxx, (b) tau_f90, and (c) tau_cc scripts.

Vulnerable Product Search on Vulmon Subscribe to Product

uoregon tau 2.16.4

Vendor Advisories

Debian Bug report logs - #506348 CVE-2008-5157: allows local users to overwrite arbitrary files via a symlink attack Package: tau; Maintainer for tau is Yann Dirson <dirson@debianorg>; Source for tau is src:tau (PTS, buildd, popcon) Reported by: Raphael Geissert <atomo64@gmailcom> Date: Thu, 20 Nov 2008 20:27:05 UT ...