Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Felipe Sateler

#34014de 53,638
7.7CVSS total
Vulnerabilidades · 2
Baixa
1
Média
1
PT-2008-4392
4.4
2008-07-01
None · Installwatch · CVE-2008-2958
**Name of the Vulnerable Software and Affected Versions** checkinstall version 1.6.1 installwatch (affected versions not specified) **Description** A race condition exists, allowing local users to overwrite arbitrary files and have other impacts via symlink and possibly other attacks on temporary working directories. **Recommendations** For checkinstall version 1.6.1, update to a newer version that contains a fix for this issue. For installwatch, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2008-3363
3.3
2008-04-16
Cecilia · Cecilia · CVE-2008-1832
**Name of the Vulnerable Software and Affected Versions** Cecilia version 2.0.5 **Description** The issue in Cecilia allows local users to overwrite arbitrary files via a symlink attack on the csvers temporary file in lib/prefs.tcl. **Recommendations** For version 2.0.5, consider restricting access to the lib/prefs.tcl file to prevent arbitrary file overwrites until a patch is available.