6.9
CVSSv2

CVE-2008-5374

Published: 08/12/2008 Updated: 19/04/2013
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

bash-doc 3.2 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/cb#####.? temporary file, related to the (1) aliasconv.sh, (2) aliasconv.bash, and (3) cshtobash scripts.

Vulnerable Product Search on Vulmon Subscribe to Product

matthias klose bash-doc 3.2

Vendor Advisories

Debian Bug report logs - #509279 CVE-2008-5374: insecure temp file handling Package: bash-doc; Maintainer for bash-doc is Matthias Klose <doko@debianorg>; Source for bash-doc is src:bash (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Sat, 20 Dec 2008 19:03:01 UTC Severity: im ...