6.9
CVSSv2

CVE-2008-6552

Published: 30/03/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.9 | Impact Score: 10 | Exploitability Score: 3.4
VMScore: 614
Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) prior to 2.03.09-1, gfs2-utils prior to 2.03.09-1, and CMAN - The Cluster Manager prior to 2.03.09-1 on Fedora 9.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat cluster project 2.01.00

redhat cluster project 2.02.00

redhat cluster project 2.03.08

redhat cluster project 2.03.09

redhat cluster project 2.99.04

redhat cluster project 2.99.05

redhat cluster project 2.99.06

redhat cluster project 2.99.13

redhat cluster project 2.03.03

redhat cluster project 2.03.04

redhat cluster project 2.99.00

redhat cluster project 2.99.01

redhat cluster project 2.99.09

redhat cluster project 2.99.10

redhat cluster project 2.00.00

redhat cluster project 2.03.05

redhat cluster project 2.03.7

redhat cluster project 2.99.02

redhat cluster project 2.99.03

redhat cluster project 2.99.11

redhat cluster project 2.99.12

redhat cluster project 2.03.00

redhat cluster project 2.03.01

redhat cluster project 2.03.10

redhat cluster project 2.03.11

redhat cluster project 2.99.07

redhat cluster project 2.99.08

redhat cman 2.03.08-1

redhat rgmanager 2.03.03-1

redhat cman 2.03.04-1

redhat cman 2.03.03-1

redhat rgmanager 2.03.07-1

redhat rgmanager 2.03.08-1

redhat cman 2.03.07-1

redhat cman 2.03.05-1

fedoraproject fedora 9

redhat rgmanager 2.03.04-1

redhat rgmanager 2.03.05-1

redhat gfs2-utils 2.03.04-1

redhat gfs2-utils 2.03.05-1

redhat gfs2-utils 2.03.07-1

redhat gfs2-utils 2.03.03-1

redhat gfs2-utils 22.03.08-1

Vendor Advisories

Multiple insecure temporary file handling vulnerabilities were discovered in Red Hat Cluster A local attacker could exploit these to overwrite arbitrary local files via symlinks (CVE-2008-4192, CVE-2008-4579, CVE-2008-4580, CVE-2008-6552) ...