6.9
CVSSv2

CVE-2008-5373

Published: 08/12/2008 Updated: 09/10/2018
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

mtx-changer.Adic-Scalar-24 in bacula-common 2.4.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mtx.##### temporary file, probably a related issue to CVE-2005-2995.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bacula bacula 2.4.2

Vendor Advisories

Debian Bug report logs - #509301 CVE-2008-5373: insecure temp file handling in mtx-changerAdic-Scalar-24 Package: bacula-common; Maintainer for bacula-common is Debian Bacula Team <pkg-bacula-devel@listsaliothdebianorg>; Source for bacula-common is src:bacula (PTS, buildd, popcon) Reported by: Steffen Joeris <steffen ...