6.9
CVSSv2

CVE-2008-5378

Published: 08/12/2008 Updated: 15/07/2009
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

arb-kill in arb 0.0.20071207.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/arb_pids_*_* temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

lehrstuhl fur mikrobiologie arb 0.0.20071207.1

Vendor Advisories

Debian Bug report logs - #508942 CVE-2008-5378: possible symlink attacks Package: arb; Maintainer for arb is Debian Med Packaging Team <debian-med-packaging@listsaliothdebianorg>; Source for arb is src:arb (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Tue, 16 Dec 2008 20:39 ...