PT-2008-5411 · Python+1 · Python+2

Jan Lieskovsky

·

Publicado

2008-09-18

·

Atualizado

2017-08-08

·

CVE-2008-4108

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5
Description The issue allows local users to potentially overwrite arbitrary files via a symlink attack on a temporary file named tmp$RANDOM.tmp. It is noted that there may not be common usage scenarios where tmp$RANDOM.tmp is located in an untrusted directory.
Recommendations For move-faqwiz.sh in Python 2.4.5, consider restricting access to the tmp directory to prevent symlink attacks on the tmp$RANDOM.tmp temporary file until a more permanent solution is available.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4108

Produtos afetados

Debian
Python
Move-Faqwiz.Sh