Verlihub · Verlihub · CVE-2008-5706
**Name of the Vulnerable Software and Affected Versions**
Verlihub versions 0.9.8d-RC2 and earlier
**Description**
The issue allows local users to overwrite arbitrary files via a symlink attack on the /tmp/trigger.tmp temporary file, specifically through the cTrigger::DoIt function in the trigger mechanism in the daemon.
**Recommendations**
For versions 0.9.8d-RC2 and earlier, consider restricting access to the cTrigger::DoIt function until a patch is available. As a temporary workaround, avoid using the trigger mechanism in the daemon to minimize the risk of exploitation.